<html><head><meta http-equiv="Content-Type" content="text/html charset=windows-1252"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; "><br><div><div>On Mon, 28 Jan 2013, at 11:07 , "Raper, William" <<a href="mailto:braper@iccohio.com">braper@iccohio.com</a>> wrote:</div><br class="Apple-interchange-newline"><blockquote type="cite"><div style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; ">On the web page for Shibboleth Identity Provider, it lists under the Key Features “Out of the box support for LDAP, Kerberos, web server and Servlet Container based authentication systems”.</div></blockquote><blockquote type="cite"><div style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; "><o:p></o:p></div><div style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; "><o:p> </o:p></div><div style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; ">Does this mean that Shibboleth Identity Provider will use an LDAP store as a source of users to authenticate, </div></blockquote><div><br></div><div>Yes. LDAP (or AD variant) or Kerberos and others may be used as the back-end source of authentication. </div><div>The relying service or application receives a SAML assertion indicating authentication (and optionally, attributes), but never sees the users' credentials.</div><br><blockquote type="cite"><div style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; ">or that it will act as a proxy for applications that use the LDAP protocol?</div></blockquote></div><br><div>No. "LDAP authentication" entails the service or application itself receives the user's credentials, turns around and attempts to bind as the user.</div><div><br></div><div>David Bantz</div><div>UA OIT IAM</div></body></html>