<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 14 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
p.MsoPlainText, li.MsoPlainText, div.MsoPlainText
        {mso-style-priority:99;
        mso-style-link:"Plain Text Char";
        margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif";}
span.PlainTextChar
        {mso-style-name:"Plain Text Char";
        mso-style-priority:99;
        mso-style-link:"Plain Text";
        font-family:"Calibri","sans-serif";}
.MsoChpDefault
        {mso-style-type:export-only;
        font-family:"Calibri","sans-serif";}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
/* List Definitions */
@list l0
        {mso-list-id:873275559;
        mso-list-type:hybrid;
        mso-list-template-ids:-1046737540 67698703 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;}
@list l0:level1
        {mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;}
@list l0:level2
        {mso-level-number-format:alpha-lower;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;}
@list l0:level3
        {mso-level-number-format:roman-lower;
        mso-level-tab-stop:none;
        mso-level-number-position:right;
        text-indent:-9.0pt;}
@list l0:level4
        {mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;}
@list l0:level5
        {mso-level-number-format:alpha-lower;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;}
@list l0:level6
        {mso-level-number-format:roman-lower;
        mso-level-tab-stop:none;
        mso-level-number-position:right;
        text-indent:-9.0pt;}
@list l0:level7
        {mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;}
@list l0:level8
        {mso-level-number-format:alpha-lower;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;}
@list l0:level9
        {mso-level-number-format:roman-lower;
        mso-level-tab-stop:none;
        mso-level-number-position:right;
        text-indent:-9.0pt;}
ol
        {margin-bottom:0in;}
ul
        {margin-bottom:0in;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoPlainText">I understand this, but this is disappointing to me for several reasons:<o:p></o:p></p>
<p class="MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class="MsoPlainText" style="margin-left:.5in;text-indent:-.25in;mso-list:l0 level1 lfo1">
<![if !supportLists]><span style="mso-list:Ignore">1.<span style="font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span><![endif]>I want to centralize configuration so I do not have to have all client systems (our suite of hosted platforms) understand how to configure various types of authentication.<o:p></o:p></p>
<p class="MsoPlainText" style="margin-left:.5in;text-indent:-.25in;mso-list:l0 level1 lfo1">
<![if !supportLists]><span style="mso-list:Ignore">2.<span style="font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span><![endif]>I want to centralize parsing of returned information so we do not have to have all client systems managing conversion of external data to a format useful for our applications. This is to some degree inevitable as the various applications
 might have different needs, but some centralization seems useful here.<o:p></o:p></p>
<p class="MsoPlainText" style="margin-left:.5in;text-indent:-.25in;mso-list:l0 level1 lfo1">
<![if !supportLists]><span style="mso-list:Ignore">3.<span style="font:7.0pt &quot;Times New Roman&quot;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</span></span><![endif]>I want a common API to provide to my application programmers who in general know nothing about authentication, SAML, LDAP, etc. What you&#8217;re providing works, but does not meet this goal.<o:p></o:p></p>
<p class="MsoPlainText"><br>
Dave.<o:p></o:p></p>
<p class="MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class="MsoPlainText">-----Original Message-----<br>
From: users-bounces@shibboleth.net [mailto:users-bounces@shibboleth.net] On Behalf Of Christopher Bongaarts<br>
Sent: Tuesday, September 18, 2012 8:05 AM<br>
To: users@shibboleth.net<br>
Subject: Re: Using Shibboleth Identity Provider for Users Authenticated on an External Shibboleth System</p>
<p class="MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class="MsoPlainText">I think a more typical approach would be to set up your own IdP to handle the non-Shibboleth authentication sources, but have your SP use the third-party IdPs directly via a discovery mechanism of some sort.<o:p></o:p></p>
<p class="MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class="MsoPlainText">On 9/17/2012 6:39 PM, Dave Eisen wrote:<o:p></o:p></p>
<p class="MsoPlainText">&gt; Greetings.<o:p></o:p></p>
<p class="MsoPlainText">&gt;<o:p>&nbsp;</o:p></p>
<p class="MsoPlainText">&gt; I am looking to develop a centralized service to provide
<o:p></o:p></p>
<p class="MsoPlainText">&gt; authentication services to all of my company&#8217;s hosted platforms. The
<o:p></o:p></p>
<p class="MsoPlainText">&gt; bulk of the users will need to be authenticated against third party
<o:p></o:p></p>
<p class="MsoPlainText">&gt; systems local to their organization. Some of the organizations use
<o:p></o:p></p>
<p class="MsoPlainText">&gt; LDAP, some use Shibboleth, some use other protocols. We do not at this
<o:p></o:p></p>
<p class="MsoPlainText">&gt; time need to maintain our own internal login/password files.<o:p></o:p></p>
<p class="MsoPlainText">&gt;<o:p>&nbsp;</o:p></p>
<p class="MsoPlainText">&gt; We will also need data acquisition services getting additional
<o:p></o:p></p>
<p class="MsoPlainText">&gt; information about these users such as email address, street address,
<o:p></o:p></p>
<p class="MsoPlainText">&gt; user type, etc.<o:p></o:p></p>
<p class="MsoPlainText">&gt;<o:p>&nbsp;</o:p></p>
<p class="MsoPlainText">&gt; The natural way to implement this would be for my company to host our
<o:p></o:p></p>
<p class="MsoPlainText">&gt; own Shibboleth Identity Provider which does whatever parsing and
<o:p></o:p></p>
<p class="MsoPlainText">&gt; configuration management needed to support this feature and then sends
<o:p></o:p></p>
<p class="MsoPlainText">&gt; the request for the &#8220;real&#8221; authentication to the third party that
<o:p></o:p></p>
<p class="MsoPlainText">&gt; knows the user. It is natural, but I do not know if it is technically possible.<o:p></o:p></p>
<p class="MsoPlainText">&gt;<o:p>&nbsp;</o:p></p>
<p class="MsoPlainText">&gt; It is clear from the Shibboleth documentation that I can forward an
<o:p></o:p></p>
<p class="MsoPlainText">&gt; authentication request to an LDAP system. I&#8217;m wondering how I support
<o:p></o:p></p>
<p class="MsoPlainText">&gt; users managed by a third party Shibboleth system.<o:p></o:p></p>
<p class="MsoPlainText">&gt;<o:p>&nbsp;</o:p></p>
<p class="MsoPlainText">&gt; Is it possible to configure my Identity Provider to authenticate user
<o:p></o:p></p>
<p class="MsoPlainText">&gt; foo using Shibboleth at bar.com&#8217;s Identify Provider? Different
<o:p></o:p></p>
<p class="MsoPlainText">&gt; Identity Providers for different users? How do I do this?<o:p></o:p></p>
<p class="MsoPlainText">&gt;<o:p>&nbsp;</o:p></p>
<p class="MsoPlainText">&gt; Thanks.<o:p></o:p></p>
<p class="MsoPlainText">&gt;<o:p>&nbsp;</o:p></p>
<p class="MsoPlainText">&gt; Dave Eisen<o:p></o:p></p>
<p class="MsoPlainText">&gt;<o:p>&nbsp;</o:p></p>
<p class="MsoPlainText">&gt; Sequoia Retail Systems<o:p></o:p></p>
<p class="MsoPlainText">&gt;<o:p>&nbsp;</o:p></p>
<p class="MsoPlainText">&gt; <a href="mailto:dkeisen@sequoiars.com"><span style="color:windowtext;text-decoration:none">dkeisen@sequoiars.com</span></a><o:p></o:p></p>
<p class="MsoPlainText">&gt;<o:p>&nbsp;</o:p></p>
<p class="MsoPlainText">&gt;<o:p>&nbsp;</o:p></p>
<p class="MsoPlainText">&gt;<o:p>&nbsp;</o:p></p>
<p class="MsoPlainText">&gt; --<o:p></o:p></p>
<p class="MsoPlainText">&gt; To unsubscribe from this list send an email to <o:p></o:p></p>
<p class="MsoPlainText">&gt; <a href="mailto:users-unsubscribe@shibboleth.net"><span style="color:windowtext;text-decoration:none">users-unsubscribe@shibboleth.net</span></a><o:p></o:p></p>
<p class="MsoPlainText">&gt;<o:p>&nbsp;</o:p></p>
<p class="MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class="MsoPlainText"><o:p>&nbsp;</o:p></p>
<p class="MsoPlainText">-- <o:p></o:p></p>
<p class="MsoPlainText">%%&nbsp; Christopher A. Bongaarts&nbsp;&nbsp; %%&nbsp; <a href="mailto:cab@umn.edu">
<span style="color:windowtext;text-decoration:none">cab@umn.edu</span></a>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; %%<o:p></o:p></p>
<p class="MsoPlainText">%%&nbsp; OIT - Identity Management&nbsp; %%&nbsp; <a href="http://umn.edu/~cab">
<span style="color:windowtext;text-decoration:none">http://umn.edu/~cab</span></a>&nbsp; %%<o:p></o:p></p>
<p class="MsoPlainText">%%&nbsp; University of Minnesota&nbsp;&nbsp;&nbsp; %%&nbsp; &#43;1 (612) 625-1809&nbsp;&nbsp;&nbsp; %%<o:p></o:p></p>
<p class="MsoPlainText">--<o:p></o:p></p>
<p class="MsoPlainText">To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">
<span style="color:windowtext;text-decoration:none">users-unsubscribe@shibboleth.net</span></a><o:p></o:p></p>
<p class="MsoPlainText"><o:p>&nbsp;</o:p></p>
</div>
</body>
</html>