<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=Windows-1252">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;">
<div>&quot;The organization prefers to leave ADFS as the main login site, <b>not allowing the users to choose what IdP.</b>”</div>
<div><br>
</div>
<div>Apart from Shibboleth being the main login site, that’s exactly what the set up we have does - not allowing users to choose what IdP. It made technical (simpler, less pieces to go wrong), user experience (one single user experience) and business (Shibboleth
 is easier to manage) sense to do it this way, which helped the organisation make a better decision than just have a whim of a preference.</div>
<div><br>
</div>
<div>If you are going to go down the harder road, I unfortunately cannot guide you.</div>
<div><br>
</div>
<div>Cheers</div>
<div>Aaron</div>
<br>
<div>
<div>On 6 Aug 2014, at 1:37 am, Domènec Sos i Vallès &lt;<a href="mailto:DSV@nextret.net">DSV@nextret.net</a>&gt; wrote:</div>
<br class="Apple-interchange-newline">
<blockquote type="cite">Date: Tue, 5 Aug 2014 14:46:48 &#43;0000<br>
From: Aaron Howell &lt;<a href="mailto:aaron.howell@deakin.edu.au">aaron.howell@deakin.edu.au</a>&gt;<br>
We made the ADFS IdP subordinate to the Shibboleth IdP. To get an ADFS session, you have to log into Shibboleth. This meant there was no need to make the Shibboleth IdP authenticate from the ADFS IdP. It made the set up quite simple. It has been working very
 well and has kept the ?S? into SSO when we were basically forced to put in ADFS.<br>
It was documented what we did here: <a href="https://wiki.shibboleth.net/confluence/display/SHIB2/MicrosoftInterop#MicrosoftInterop-UsingShibbolethIdPasauthenticationsourceforADFS">
https://wiki.shibboleth.net/confluence/display/SHIB2/MicrosoftInterop#MicrosoftInterop-UsingShibbolethIdPasauthenticationsourceforADFS</a><br>
Hope that helps<br>
<br>
Thanks Aaron and Scott for the fast reply. <br>
<br>
My current setup is based on [1] where ADFS acts as a &quot;gateway&quot; for Shibboleth (Shibboleth is a claims provider trust of ADFS, ADFS is a relying party of Shibboleth).<br>
[1] <a href="http://download.microsoft.com/documents/France/Interop/2010/Federated_Collaboration_With_Shibboleth_2_0_and_SharePoint_2010_technologies-1_0.docx">
http://download.microsoft.com/documents/France/Interop/2010/Federated_Collaboration_With_Shibboleth_2_0_and_SharePoint_2010_technologies-1_0.docx</a><br>
If the user is authenticated by Shibboleth, he/she can access any relying party of both ADFS and Shibboleth.<br>
If the user is authenticated by ADFS, when accessing a Shibboleth relying party a second login into Shibboleth will be needed the first time.<br>
The organization prefers to leave ADFS as the main login site, not allowing the users to choose what IdP.<br>
<br>
I have to read in depth the &quot;AD FS 2.0 Step-by-Step Guide: Federation with Shibboleth 2 and the InCommon Federation&quot; pointed by Aaron's wiki suggestion (and reviewed by Scott Cantor himself).
<br>
<br>
Question: Will installing the Shibboleth SP in my current Shibboleth IdP (as per step 2) allow it to work as a relying party of the ADFS IdP? The document shows how the ADFS authenticated user can access a Shibboleth SP protected application, but it is unclear
 to me whether it would work for accessing a relying party of the Shibbolet IdP (that is, Google Apps, Zendesk...)<br>
<br>
-- <br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">
users-unsubscribe@shibboleth.net</a><br>
</blockquote>
</div>
<br>
<span style="font-size: 9.0pt; font-family: 'Calibri'; "><em><strong><br>
Important Notice:</strong> The contents of this email are intended solely for the named addressee and are confidential; any unauthorised use, reproduction or storage of the contents is expressly prohibited. If you have received this email in error, please delete
 it and any attachments immediately and advise the sender by return email or telephone.<br>
<br>
Deakin University does not warrant that this email and any attachments are error or virus free.</em></span>
</body>
</html>