<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0cm;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif";
        mso-fareast-language:EN-US;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:#0563C1;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:#954F72;
        text-decoration:underline;}
span.EstiloCorreo17
        {mso-style-type:personal-compose;
        font-family:"Calibri","sans-serif";
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-family:"Calibri","sans-serif";
        mso-fareast-language:EN-US;}
@page WordSection1
        {size:612.0pt 792.0pt;
        margin:70.85pt 3.0cm 70.85pt 3.0cm;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="ES" link="#0563C1" vlink="#954F72">
<div class="WordSection1">
<p class="MsoNormal"><span lang="EN-GB">Hello,<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB"><o:p>&nbsp;</o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB">the organization I am working at has two IdP in a test stage about to go to production as part of an ongoing SSO initiative:<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB"><o:p>&nbsp;</o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB">- ADFS v2, whose relying parties are Sharepoint sites (previously using MS TMG SSO), ASP .Net applications (no previous SSO), ex-novo Wordpress sites using the plugin based on simpleSAMLphp, Outlook mail (we leveraged
 the initial ADFS installation), and one external application in the cloud, Salesforce (no previous SSO).<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB"><o:p>&nbsp;</o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB">- Shibboleth 2.4, whose relying parties are several applications that will be migrated from CAS in the coming months, several cloud services (Blackboard, Zendesk, Google Apps...) and one relying party as a PHP application
 with simpleSAMLphp (BTW, nice little piece of software it is)<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB"><o:p>&nbsp;</o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB">Reasons for having two IdP include long internal discussions that I don't want you to be bored with.<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB"><o:p>&nbsp;</o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB">As of now, and following a Microsoft guide, Shibboleth is a trusted claims provider for ADFS, and ADFS is a relying party for Shibboleth. This means that people can log in Shibboleth and access Sharepoint sites, ASP .Net
 apps, etc (except Outlook, which would have been too much sorcery to watch for the Microsoft guys, but I guess it would work with some proper claims transformation rule in ADFS).<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB"><o:p>&nbsp;</o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB">All of this (except the CAS apps) has been tested in a laptop based VirtualBox laboratory environment and in a pre-production test environment.<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB"><o:p>&nbsp;</o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB">What is missing is to have ADFS as a valid IdP for the Shibboleth relying parties, and that sounds as &quot;federation&quot;. I have done some RTFM and tried to learn from example, and at this point I will highly appreciate some
 &quot;been there, done that&quot; point of view, ideas, criticism, and URL formatted values for M in further RTFM.<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB"><o:p>&nbsp;</o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB">For setting up the federation I got much enlightenment and an example from<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB">https://www.switch.ch/aai/docs/shibboleth/SWITCH/latest/idp/deployment/#shibboleth-idp-configuration<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB">and some ideas from this, although it is Tivoli oriented.<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB">http://technet.microsoft.com/en-us/library/gg749921(v=ws.10).aspx<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB"><o:p>&nbsp;</o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB">This seems to be not what I am looking for, as it sets a Shibboleth *SP* as a relying party of the ADFS, but not a federation between both IdP. The InCommon Appendix is a bit incomplete in comparison to the body of the
 article:<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB">http://technet.microsoft.com/en-us/library/gg317734(WS.10).aspx<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB"><o:p>&nbsp;</o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB">So, my view of what should be done is:<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB"><o:p>&nbsp;</o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB">For Shibboleth;<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB"><o:p>&nbsp;</o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB">- For the Shibboleth IdP, a federation metadata setup similar to the one explained by SWITCH.ch, including both ADFS and Shibboleth as IDPSSODescriptors. ADFS metadata will be prepared as in the Tivoli example (which
 I trust to be SAML 2.0 compliant). This is the mirror of declaring Shibboleth as a trusted claims provider in ADFS.<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB"><o:p>&nbsp;</o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB">- Remove the definition of ADFS as a Shibboleth relying party, considering it will now be a federation peer as per the federation metadata.<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB"><o:p>&nbsp;</o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB">- No need to add a Shibboleth SP anywhere for federation purposes (applications moving from CAS may, but in order to become Shibboleth relying parties)<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB"><o:p>&nbsp;</o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB">For ADFS:<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB"><o:p>&nbsp;</o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB">- Leave &quot;as is&quot; the ADFS claims provider trust for Shibboleth. That would be the part of importing federation metadata, provided ADFS does not allow importing multiple entity descriptors. I should check the results of
 applying the FEMMA tool to the federation metadata and see if the result would be similar to what I have.<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB"><o:p>&nbsp;</o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB">I understand that the effect for Shibboleth of declaring ADFS a part of the federation mirrors declaring Shibboleth as a trusted claims provider for ADFS. From here, each IdP will transfer to their relying parties the
 claims that were received by the opposite trusted claims provider or federation peer.<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB"><o:p>&nbsp;</o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB">All ideas are welcome and appreciated, thanks in advance.<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB"><o:p>&nbsp;</o:p></span></p>
<p class="MsoNormal">/Domenec<o:p></o:p></p>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
</body>
</html>