<div dir="ltr"><div><div><div></div>Thank you for the point of clarification Peter. I guess my question was more along the lines of whether Google provides POP/IMAP servers doing a similar proxy scenario using ECP like Microsoft has done in O365 vs ECP in the purest form.<br>
<br></div>I'm also a little unsure even if they did provide that, would it be enough to take care of syncing with Android phones? Last I checked, the sync profiles for setting up a Google account on Android device didn't use the embedded browser tactic and seemed to have a little more going on that just straight up being a POP/IMAP client.<br>
<br></div><div>I'm curious how Google schools deploying shibb for an SSO deal with the mobile device issue since accessing email on handheld devices has become a fundamental expectation... do most still send your passwords to Google for local auth in conjunction with SSO for the web components as we are, or is there a better approach? <br>
</div><div><br></div>-Rob<br><br></div><div class="gmail_extra"><br><br><div class="gmail_quote">On Mon, Aug 4, 2014 at 10:21 AM, Peter Schober <span dir="ltr"><<a href="mailto:peter.schober@univie.ac.at" target="_blank">peter.schober@univie.ac.at</a>></span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">* Rob Gorrell <<a href="mailto:rwgorrel@uncg.edu">rwgorrel@uncg.edu</a>> [2014-08-04 16:14]:<br>
<div class="">> We were an early GAFE subscriber, and while not shibb, have always used a<br>
> SAML based SSO login, but also synced passwords for other non-SSO services<br>
> to work. Correct me if I'm wrong, but I'm thinking I should be able to<br>
> replace this with shibb + ECP and omit the need to send passwords to<br>
> google? Are there any google apps that anyone is aware of where shibb's<br>
> SAML2 and ECP profiles would not cover the authentication needs?<br>
<br>
</div>Using ECP for e.g. IMAP access requires ECP-awareness in both the IMAP<br>
client as well as the IMAP server, none of which exist, AFAIU.<br>
The reason this works with some hosted M$ products is because you're<br>
sending username and password to a proxy run by M$ that just uses ECP<br>
to verify the crendials with your IDP (like it was done in the old<br>
days with LDAP), it's not the mail client that does ECP to the IMAP<br>
server.<br>
All that is fully independent from the question whether Google Apps<br>
actually support ECP, about which I can't recall hearing anything (but<br>
then I'm not using an of their services) and which would render the<br>
above moot, of course.<br>
<span class="HOEnZb"><font color="#888888">-peter<br>
</font></span><div class="HOEnZb"><div class="h5">--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br><br clear="all"><br>-- <br><div dir="ltr"><div>Robert W. Gorrell<br>Systems Architect, Identity and Access Management </div>
<div>University of NC at Greensboro<br><span style="white-space:nowrap">336-334-5954</span><br>PGP Key ID B36DB0CA<br></div></div>
</div>