<div dir="ltr">Well, maybe you should contact the CiLogon people, as CiLogon<div>is designed to issue certificates based on some other authentication,</div><div>such as using Shibboleth from some InCommon IDP. </div><div><br>
</div><div>These certificates can then be used with Globus, including</div><div>GSI-OpenSSH. </div><div> <br></div><div>I am now retired, but had used our IDP to get certificates from CiLogon.</div><div>I was involved with Globus and GSI in the pass too. </div>
<div><br></div><div>I never did try using a CiLogon certificate with our IDP, which has</div><div>the X509-login-handler. The IDP only trusted the local enterprise CA and </div><div>PIV smart cards. With any certificate the IDP still needed to map the certificate to some local user for authorization.</div>
<div><br></div><div>(Also see RFC 3280 that defines the proxy certificates used with GSI.)</div><div><br></div><div>So it is still not clear what you are trying do with Shibboleth and CiLogin.</div><div><br></div><div>But your IDP may already be setup to work with CiLogon as the SP to<br>
</div><div>get certificates.</div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br>
</div><div><br></div><div><br></div><div> </div><div><br></div></div><div class="gmail_extra"><br><br><div class="gmail_quote">On Fri, Feb 28, 2014 at 7:57 PM, Douglas E Engert <span dir="ltr">&lt;<a href="mailto:deengert@gmail.com" target="_blank">deengert@gmail.com</a>&gt;</span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr"><div>Let me also add, that if you have CiLogon certificates, you could use them</div><div>for authentication to an IDP, using the X509-login-handler.</div>
</div><div class="HOEnZb"><div class="h5"><div class="gmail_extra"><br><br><div class="gmail_quote">
On Fri, Feb 28, 2014 at 4:06 PM, Douglas E Engert <span dir="ltr">&lt;<a href="mailto:deengert@gmail.com" target="_blank">deengert@gmail.com</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">

<div dir="ltr"><div>CiLogon is in InCommon, So if your IDP is in InCommon, CiLogon </div><div>should be all set to issue you certificates. </div><div><br></div><div><a href="http://www.cilogon.org/" target="_blank">http://www.cilogon.org/</a></div>


<div><br></div><div>How you use the certificates may be outside of Shibboleth. </div><div><br></div></div><div class="gmail_extra"><br><br><div class="gmail_quote"><div><div>On Thu, Feb 27, 2014 at 6:57 PM, Bryan E. Wooten <span dir="ltr">&lt;<a href="mailto:bryan.wooten@utah.edu" target="_blank">bryan.wooten@utah.edu</a>&gt;</span> wrote:<br>


</div></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;padding-left:1ex;border-left-color:rgb(204,204,204);border-left-width:1px;border-left-style:solid"><div><div>



<div style="font-family:Calibri,sans-serif;font-size:14px">
<div>So I have been asked to participate in the CC*IIE grant. CILogin is part of the whole supercomputer IDM space and this grant. Think ECP, which I have exactly zero experience.</div>
<div><br>
</div>
<div>Any direction, help, guidance, resources is most appreciated.</div>
<div><br>
</div>
<div>What do I need to do as an IDP?</div>
<div><br>
</div>
<div>Cheers,</div>
<div><br>
</div>
<div>Bryan</div>
</div>

<br></div></div><div>--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br></div></blockquote></div><br></div>
</blockquote></div><br></div>
</div></div></blockquote></div><br></div>