Thanks Nate. That is a very useful page. I have also searched around and found that Salesforce is using SAML + OAuth to authenticate and authorize native client:<br> <a href="http://wiki.developerforce.com/page/Single_Sign-On_for_Desktop_and_Mobile_Applications_using_SAML_and_OAuth">http://wiki.developerforce.com/page/Single_Sign-On_for_Desktop_and_Mobile_Applications_using_SAML_and_OAuth</a><br>
<br>Are you familiar with this approach? Is it widely used? It seems that in order to continue with this approach the critical part is that SP needs to support SAML and OAuth, and native client needs to support OAuth.<br>
<br>I also see some articles about combining SAML and OAuth together, any comments with it?<br><br>Comparing with ECP approach, what are the pros and cons? <br><br>I also remember somewhere in the wiki I saw that in the new SAML version, you are going to further standardize the ECP method, especially the interaction between client and IdP for authentication. Any more details?<br>
<br><br clear="all">Yaowen<br>
<br><br><div class="gmail_quote">On Fri, Aug 31, 2012 at 9:44 PM, Nate Klingenstein <span dir="ltr"><<a href="mailto:ndk@internet2.edu" target="_blank">ndk@internet2.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
Yaowen,<br>
<br>
That's exactly one of the approaches. You may find the NET+ Identity<br>
Guidance for Services non-browser access section a good place to get<br>
some more ideas. It's not very specific and technical though, because<br>
we can't get specific about the huge variety of applications and<br>
protocols in the world.<br>
<br>
<a href="https://spaces.internet2.edu/display/NetPlusIDG/NET+Plus+Identity+Guidance+for+Services" target="_blank">https://spaces.internet2.edu/display/NetPlusIDG/NET+Plus+Identity+Guidance+for+Services</a><br>
#NETPlusIdentityGuidanceforServices-6.NonBrowserAccess<br>
<br>
Take care,<br>
Nate.<br>
<div class="im HOEnZb"><br>
On Sep 1, 2012, at 4:40 , Yaowen Tu wrote:<br>
<br>
> Do you know how SAML users achieve mobile app login? Is this where<br>
> ECP should be considered?<br>
<br>
</div><div class="HOEnZb"><div class="h5">--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br>