<html>
<head>
</head>
<body class='hmmessage'><div dir='ltr'>

<style><!--
.hmmessage P
{
margin:0px;
padding:0px
}
body.hmmessage
{
font-size: 12pt;
font-family:Calibri
}
--></style>
<div dir="ltr">ADFS is like Shibboleth in that it does not produce a Windows server security context equivalent to the IIS Windows Integrated Auth.&nbsp; This in-memory context contains the SIDs of the user and the security groups the user is a member of and the SID histories and is used by Windows to control access to resources that are ACL'd with SIDs (among other things).</div><div dir="ltr">&nbsp;</div><div dir="ltr">There is a&nbsp;Windows service called the C2WTS - Claims to Windows Token Service that constructs a true windows login based on assertions.&nbsp; This C2WTS is fairly easy to use with ADFS.&nbsp; I do not know how hard it would be to adapt it to a Shibboleth SP.<br><br>Randy<br><br>&nbsp;<br></div><div dir="ltr">&gt; Date: Fri, 19 Jul 2013 10:41:36 -0700<br>&gt; From: david.tello@whitebearsolutions.com<br>&gt; To: users@shibboleth.net<br>&gt; Subject: RE: Shibboleth SP and IIS authentication<br>&gt; <br>&gt; ooooohhh shit....<br>&gt; <br>&gt; I was afraid that it wouldn't be possible. I must to study use ADFS, but i<br>&gt; didn't want. Thanks for your reply Scott!!<br>&gt; <br>&gt; <br>&gt; <br>&gt; <br>&gt; --<br>&gt; View this message in context: http://shibboleth.1660669.n2.nabble.com/Shibboleth-SP-and-IIS-authentication-tp7588646p7588658.html<br>&gt; Sent from the Shibboleth - Users mailing list archive at Nabble.com.<br>&gt; --<br>&gt; To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br></div>
                                               </div></body>
</html>