<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<style>
<!--
@font-face
        {font-family:"Cambria Math"}
@font-face
        {font-family:Calibri}
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif"}
a:link, span.MsoHyperlink
        {color:blue;
        text-decoration:underline}
a:visited, span.MsoHyperlinkFollowed
        {color:purple;
        text-decoration:underline}
span.EmailStyle17
        {font-family:"Calibri","sans-serif";
        color:windowtext}
.MsoChpDefault
        {}
@page WordSection1
        {margin:1.0in 1.0in 1.0in 1.0in}
div.WordSection1
        {}
-->
</style>
</head>
<body lang="EN-US" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal">Hi,</p>
<p class="MsoNormal">&nbsp;</p>
<p class="MsoNormal">Part of my job at Emory University is to help people here who are seeking to Shibbolize web applications.</p>
<p class="MsoNormal">&nbsp;</p>
<p class="MsoNormal">Has anyone gotten SSO to work between an application running on IBM's WebSphere application server (version 8.5) and a Shibbolized application running in a non-WebSphere environment?</p>
<p class="MsoNormal">&nbsp;</p>
<p class="MsoNormal">The desired usage scenario is that an attempt to access either application without a Shibboleth session initiates a Shibboleth IdP login, and after the Shibboleth login, the user can immediately access either application as an authenticated
 user of that environment without being asked to login again.</p>
<p class="MsoNormal">&nbsp;</p>
<p class="MsoNormal">The above description is slightly simplified in that it does not discuss all the sessions that might be involved.</p>
<p class="MsoNormal">&nbsp;</p>
<p class="MsoNormal">The IBM folks I talked to could pronounce Shibboleth correctly and said they support SAML, but otherwise said they did not know how WebSphere security worked and knew nothing about Shibboleth. From what I have been able to learn by Googling
 around, WebSphere can support SAML 2.0 Web Single Sign-on, and can run behind Apache HTTP. However, the examples I found seem to always use IBM software-specific sessions and work between instances of WebSphere.</p>
<p class="MsoNormal">&nbsp;</p>
<p class="MsoNormal">Thinking about how the scenario might be implemented leads to the question: Has anyone Shibbolized IBM's WebSphere application server?</p>
<p class="MsoNormal">&nbsp;</p>
<p class="MsoNormal">Any ideas about getting this to work would be appreciated.</p>
<p class="MsoNormal">&nbsp;</p>
<p class="MsoNormal">Thanks!</p>
<p class="MsoNormal">Peter Day</p>
<p class="MsoNormal">Enterprise Middleware Admin</p>
<p class="MsoNormal">Emory University</p>
</div>
<br>
<hr>
<font face="Arial" color="Gray" size="1"><br>
This e-mail message (including any attachments) is for the sole use of<br>
the intended recipient(s) and may contain confidential and privileged<br>
information. If the reader of this message is not the intended<br>
recipient, you are hereby notified that any dissemination, distribution<br>
or copying of this message (including any attachments) is strictly<br>
prohibited.<br>
<br>
If you have received this message in error, please contact<br>
the sender by reply e-mail message and destroy all copies of the<br>
original message (including attachments).<br>
</font>
</body>
</html>