<html><head><meta content="text/html; charset=utf-8" http-equiv="Content-Type"></head><body><div><div style="font-family:Calibri,sans-serif;font-size:11pt">Every account should have IMAP access enable but that&#39;s a nice idea!<br>
<br></div></div><hr><span style="font-family:Tahoma,sans-serif;font-size:10pt;font-weight:bold">De : </span><span style="font-family:Tahoma,sans-serif;font-size:10pt">Glenn Wearen</span><br><span style="font-family:Tahoma,sans-serif;font-size:10pt;font-weight:bold">Envoyé : </span><span style="font-family:Tahoma,sans-serif;font-size:10pt">10/10/2012 17:51</span><br>
<span style="font-family:Tahoma,sans-serif;font-size:10pt;font-weight:bold">À : </span><span style="font-family:Tahoma,sans-serif;font-size:10pt">Shib Users</span><br><span style="font-family:Tahoma,sans-serif;font-size:10pt;font-weight:bold">Objet : </span><span style="font-family:Tahoma,sans-serif;font-size:10pt">Re: Google ID as sort of the IDP?</span><br>
<br></body></html><html><head></head><body style="word-wrap:break-word"><div>You can use a jaas compliant imap authenticator but you&#39;ll need a data source for your resolver if you need any attribute other than principal</div>
<div><br></div><div><a href="http://sourceforge.net/projects/jaas-rimap/">http://sourceforge.net/projects/jaas-rimap/</a> is in production at one IdP hat I&#39;m aware of and seems quite reliable.</div><div><br></div><div>
Regards</div><div>Glenn</div><div><br></div><div><br></div><div>
<div style="word-wrap:break-word"><div><div><a href="http://www.edugate.ie">Edugate</a> Operations</div><div><a href="http://www.heanet.ie">HEAnet Limited</a>, Ireland&#39;s Education and Research Network - </div><div>1st Floor, 5 George&#39;s Dock, IFSC, Dublin 1</div>
<div>Registered in Ireland, no 275301  tel: +353-1-6609040  fax: +353-1-6603666</div></div></div>
</div>
<br><div><div>On 10 Oct 2012, at 15:05, Yannick Béot wrote:</div><br class="Apple-interchange-newline"><blockquote type="cite">Hi, <div>Google cannot work as a SAML IdP per se, even though it supports SAML 2.0 as a service provider (from your IdP to Google Apps).<div>
<br></div><div>If you want to delegate the authentication to you Idp to Google Apps, you would have to implement OAUTH (<a href="https://developers.google.com/accounts/docs/AuthForWebApps">https://developers.google.com/accounts/docs/AuthForWebApps</a>) as an authentication provider for IdP. It&#39;s possible technically speaking I think.</div>

<div><br></div><div>Y.</div><div><br></div><div><br><div><br><div class="gmail_quote">On Tue, Oct 9, 2012 at 10:55 PM, Oleg Chaikovsky <span dir="ltr">&lt;<a href="mailto:oleg.chaikovsky@aegisusa.net" target="_blank">oleg.chaikovsky@aegisusa.net</a>&gt;</span> wrote:<br>

<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">I have seen the large amounts of information about connecting Google<br>
Apps via Shib which is fairly straightforward at this point. Google Apps<br>
as an SP.<br>
<br>
So - now - if a group wanted to make their Google Apps domain to be the<br>
primary identifier for all of their other apps - would that simply be<br>
using external auth through the IdP? Simple as that? I keep thinking<br>
there must be more to it but all info I have read on the Wiki points to<br>
that model. (there are no additional attributes to consider in this idea).<br>
<span class="HOEnZb"><font color="#888888"><br>
--<br>
Oleg Chaikovsky<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</font></span></blockquote></div><br></div></div></div>
--<br>To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a></blockquote></div><br></body></html>