<div dir="ltr">Got it. Thank you so much again.<br></div><div class="gmail_extra"><br clear="all"><div>Yaowen</div>
<br><br><div class="gmail_quote">On Mon, May 6, 2013 at 11:39 AM, Mike Flynn <span dir="ltr">&lt;<a href="mailto:shibbolethlynda@yahoo.com" target="_blank">shibbolethlynda@yahoo.com</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">

<div><div style="font-size:12pt;font-family:arial,helvetica,sans-serif"><div><span>FWIW, our system uses a separate login for administrators to manage account options and produce reports.  All other users go through SSO.  </span></div>

<div><br></div>  <div style="font-family:arial,helvetica,sans-serif;font-size:12pt"> <div style="font-family:&#39;times new roman&#39;,&#39;new york&#39;,times,serif;font-size:12pt"> <div dir="ltr"> <hr size="1">  <font face="Arial"> <b><span style="font-weight:bold">From:</span></b> Yaowen Tu &lt;<a href="mailto:yaowen.tu@gmail.com" target="_blank">yaowen.tu@gmail.com</a>&gt;<br>

 <b><span style="font-weight:bold">To:</span></b> Shib Users &lt;<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>&gt; <br> <b><span style="font-weight:bold">Sent:</span></b> Monday, May 6, 2013 11:25 AM<br>

 <b><span style="font-weight:bold">Subject:</span></b> Re: Question about initial user/role setup after enabling SAML SSO<br> </font> </div><div><div class="h5"> <div><br><div><div dir="ltr"><div><div><div>David,<br><br>
Thank you so much. I really appreciate it. Can I have two follow up questions?<br>
<br></div>1. For solution 1, we know this is the preferred way, but we have some concerns. can you tell me a bit more details about as an SP how to support this?  Do you return role information in Assertion? What if SP has a different set of roles than IdP? Does SP need to define some kind of mapping? What if in SP we have more detailed roles like(admin, operator, reader, manager), but not all the roles are existing in IdP system?<br>



<br></div>2. For your Option3, I don&#39;t quite get what you mean. Can you tell me how do you achieve this: &quot;You setup the initial SSO with me and I&#39;ll send a user across with the Administrator role in the assertion.&quot;?<br>



<br></div>Thanks,<br>Yaowen<br></div><div><br clear="all"><div>Yaowen</div>
<br><br><div>On Mon, May 6, 2013 at 7:45 AM, David Langenberg <span dir="ltr">&lt;<a rel="nofollow" href="mailto:davel@uchicago.edu" target="_blank">davel@uchicago.edu</a>&gt;</span> wrote:<br><blockquote style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">



On May 5, 2013, at 7:29 PM, Yaowen Tu &lt;<a rel="nofollow" href="mailto:yaowen.tu@gmail.com" target="_blank">yaowen.tu@gmail.com</a>&gt;<br>
<div> wrote:<br>
<br>
&gt; Hi,<br>
&gt;<br>
&gt; This question is not about how to integrate with SAML or how to use Shib products. But I am pretty sure people here have had the same problem that I am facing, so I am just looking for some advices. If it is not the correct place, please let me know.<br>




&gt;<br>
&gt; We are a service provider, and we are using Shibboleth SP. Suppose in our application, we originally have our own user/role management. Different users with different roles are allowed to use different features. So that when a user login we need to know which roles this user has, and prepare appropriate UI. We have administrator role, users with this role can assign roles to other users.<br>




&gt;<br>
&gt; We are thinking of enabling SAML SSO for our application, now the problem is how do we setup roles for each user.<br>
&gt;<br>
&gt; Solution 1, we relies on IdP to provide role information for each login user, the role information may come along with Assertion, but this may not work for all the IdPs.<br>
<br>
</div>This would be our preferred method.  Several SPs that we integrate with have us do this, and it&#39;s very convenient in that it makes it extremely easy for us to tie in your SPs authorization settings with our central authorization database (we use Grouper by Internet2).  This way as users turn-over the service admin does not have to do anything special in regards to managing user roles.  Now, the one request I would make if you do go this route is to NOT require that a user have only ONE single role.  Rather, be able to handle the case of a user coming in with more than one role applied to them.  If two roles are completely orthogonal to each-other use a UI element in the application to allow the user to choose which role they&#39;d like to use for this session.<br>




<div><br>
&gt; Solution 2, we only retrieve user from the IdP, and manage the roles in our own application. For example, when we get an Assertion, we retrieve the username(or email address), and match with a record in our DB, if it doesn&#39;t exist we automatically create one for this new user. Then we rely on users with administrator role to assign correct role for this new user.<br>




<br>
</div>This is a bigger pain to manage at scale as it means either writing custom integration software to manage roles in your app, or hiring a person to do it.  Certainly increases overhead and costs associated with using your product.<br>




<div><br>
&gt;<br>
&gt; Now the questions is where is the first administrator coming from? Our customer gets our application, and turns on SAML SSO, now there is no users in the DB yet, then how can we resolve such bootstrapping issue? Is there any kinds of standard way? We have come up with different options but not sure which is better and what are the concerns for each options.<br>




&gt;<br>
&gt; Option 1, have a default built-in administrator user. There is a regular native login page that built-in users can login without going through IdP(there is an option to turn it on/off if SAML SSO is enabled)<br>
<br>
</div>This is typically how I&#39;ve seen it done.  It is also good in that if the SSO system goes offline for whatever reason, the admin can still get into your app.<br>
<div><br>
&gt;<br>
&gt; Option 2, during SAML SSO setup, ask for the administrator user name, so that we automatically create this user in our DB with administrator role. Then when this user login through IdP we could match him in our DB.<br>




<br>
</div>Not as common, but a couple of our vendors went this route.<br>
<br>
<br>
Option 3: you provision on first login.  You setup the initial SSO with me and I&#39;ll send a user across with the Administrator role in the assertion.  Their account is automatically created and they&#39;re dumped into the app in admin mode.<br>




<br>
Dave<br>
<br>
--<br>
David Langenberg<br>
Identity &amp; Access Management<br>
The University of Chicago<br>
--<br>
To unsubscribe from this list send an email to <a rel="nofollow" href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div><br></div></div><br>--<br>To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br><br></div> </div></div>

</div> </div>  </div></div><br>--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br></blockquote></div><br></div>