<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<!--[if !mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]--><style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Tahoma;
        panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
p.msochpdefault, li.msochpdefault, div.msochpdefault
        {mso-style-name:msochpdefault;
        mso-margin-top-alt:auto;
        margin-right:0in;
        mso-margin-bottom-alt:auto;
        margin-left:0in;
        font-size:10.0pt;
        font-family:"Times New Roman",serif;}
span.emailstyle17
        {mso-style-name:emailstyle17;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
span.emailstyle18
        {mso-style-name:emailstyle18;
        font-family:"Calibri",sans-serif;
        color:#1F497D;}
span.EmailStyle20
        {mso-style-type:personal-reply;
        font-family:"Calibri",sans-serif;
        color:#1F497D;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal"><span style="color:black">We are looking at our options for Shib and SPNEGO Kerberos support and Chris Franks (the technical genius behind the SPNEGO work) is currently sorting out our shib3 roadmap. We have over 100 internal SPs so we
are heavily motivated to come up with a working solution, from what we have seen so far we should be able to get something workable. We’ll let the list now when we get to something concrete.
<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:black"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:black"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:black">To answer Dave’s question re login with role accounts there are a couple of options, you can alter the
</span><span style="color:black">spnegoscript.js script so it looks for a user agent string (campus-ncl) in our case and only autologins in when it sees that (we than apply that change to our IE and Chrome builds) Then when you don’t what to autologin unset
the useragent stirng. Alternatively change the browser security setting so that it doesn’t send kerb tickets to anything (IIRC setting IE security to “High” might do the trick)<o:p></o:p></span></p>
<p class="MsoNormal"><b><o:p> </o:p></b></p>
<p class="MsoNormal"><b><o:p> </o:p></b></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<div style="border:none;border-left:solid blue 1.5pt;padding:0in 0in 0in 4.0pt">
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b>From:</b> users-bounces@shibboleth.net [mailto:users-bounces@shibboleth.net]
<b>On Behalf Of </b>Cesc Travesa<br>
<b>Sent:</b> Thursday, March 26, 2015 2:15 AM<br>
<b>To:</b> Shib Users<br>
<b>Subject:</b> Re: Kerberos Authentication<o:p></o:p></p>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<div>
<p class="MsoNormal"><span lang="EN-GB" style="font-size:10.0pt;font-family:"Tahoma",sans-serif;color:black">Hi All,
<o:p></o:p></span></p>
<div>
<p class="MsoNormal"><span lang="EN-GB" style="font-size:10.0pt;font-family:"Tahoma",sans-serif;color:black"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span lang="EN-GB" style="font-size:10.0pt;font-family:"Tahoma",sans-serif;color:black">This documentation (<a href="https://crypt.ncl.ac.uk/login-gateway/docs/Shibboleth_SPNEGO_Setup.pdf" target="_blank"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif">https://crypt.ncl.ac.uk/login-gateway/docs/Shibboleth_SPNEGO_Setup.pdf</span></a>) is
for IdP v2.x isn't it? in v3.0 can't be reused right?<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span lang="EN-GB" style="font-size:10.0pt;font-family:"Tahoma",sans-serif;color:black"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span lang="EN-GB" style="font-size:10.0pt;font-family:"Tahoma",sans-serif;color:black">Any news on approximate IdP release of when the "magical kerberos" will be working?<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span lang="EN-GB" style="font-size:10.0pt;font-family:"Tahoma",sans-serif;color:black"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span lang="EN-GB" style="font-size:10.0pt;font-family:"Tahoma",sans-serif;color:black">Cesc<o:p></o:p></span></p>
<div>
<div class="MsoNormal" align="center" style="text-align:center"><span lang="EN-GB" style="font-size:12.0pt;font-family:"Times New Roman",serif;color:black">
<hr size="2" width="100%" align="center">
</span></div>
<div id="divRpF174365">
<p class="MsoNormal" style="margin-bottom:12.0pt"><b><span lang="EN-GB" style="font-size:10.0pt;font-family:"Tahoma",sans-serif;color:black">De:</span></b><span lang="EN-GB" style="font-size:10.0pt;font-family:"Tahoma",sans-serif;color:black">
<a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a> [users-bounces@shibboleth.net] en nombre de Dave Perry [Dave.Perry@hull-college.ac.uk]<br>
<b>Enviado:</b> miércoles, 04 de marzo de 2015 1:24<br>
<b>Para:</b> Shib Users<br>
<b>Asunto:</b> RE: Kerberos Authentication</span><span lang="EN-GB" style="font-size:12.0pt;font-family:"Times New Roman",serif;color:black"><o:p></o:p></span></p>
</div>
<div>
<div>
<p class="MsoNormal"><span lang="EN-GB" style="color:#1F497D">See here:</span><span lang="EN-GB" style="color:black"><o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB" style="color:#1F497D"><a href="https://crypt.ncl.ac.uk/login-gateway/docs/Shibboleth_SPNEGO_Setup.pdf" target="_blank">https://crypt.ncl.ac.uk/login-gateway/docs/Shibboleth_SPNEGO_Setup.pdf</a></span><span lang="EN-GB" style="color:black"><o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB" style="color:#1F497D"> </span><span lang="EN-GB" style="color:black"><o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB" style="color:#1F497D">Caleb – is there a way of giving people the option of not using this on a per-use basis? We’ve found that some people need to login to our shibboleth as not the user logged in to the PC (i.e. us
elearning/IT folk when testing things for people).</span><span lang="EN-GB" style="color:black"><o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB" style="color:#1F497D">I was going to factor it in to our new (v3) IdP from the getgo, but a little hesitant if it can’t (moodle lets us login without checking the NTLM status with a bypass link, does your SPENGO setup?).</span><span lang="EN-GB" style="color:black"><o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB" style="color:#1F497D"> </span><span lang="EN-GB" style="color:black"><o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB" style="color:#1F497D"> </span><span lang="EN-GB" style="color:black"><o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB" style="color:#1F497D">Dave</span><span lang="EN-GB" style="color:black"><o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB" style="color:#1F497D"> </span><span lang="EN-GB" style="color:black"><o:p></o:p></span></p>
<div>
<p class="MsoNormal"><span lang="EN-GB" style="font-size:10.0pt;font-family:"Tahoma",sans-serif;color:#1F497D">_________________________________________________</span><span lang="EN-GB" style="color:black"><o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB" style="font-size:10.0pt;font-family:"Tahoma",sans-serif;color:#1F497D">Dave Perry<br>
eLearning Technologist, Hull College Group<br>
<br>
Room L34 - Queens Gardens Library<br>
Wilberforce Drive, Queen's Gardens, Hull, HU1 3DG<br>
Extension 2230 / Direct Dial 01482 381930</span><span lang="EN-GB" style="color:black"><o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB" style="font-size:10.0pt;font-family:"Tahoma",sans-serif;color:#1F497D"> </span><span lang="EN-GB" style="color:black"><o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB" style="font-size:10.0pt;font-family:"Tahoma",sans-serif;color:#1F497D">* Need a fast reply? Try
<a href="mailto:elearning@hull-college.ac.uk" target="_blank">elearning@hull-college.ac.uk</a> *</span><span lang="EN-GB" style="color:black"><o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB" style="font-size:10.0pt;font-family:"Tahoma",sans-serif;color:#1F497D"> </span><span lang="EN-GB" style="color:black"><o:p></o:p></span></p>
<p class="MsoNormal"><b><span lang="EN-GB" style="font-size:10.0pt;font-family:"Tahoma",sans-serif;color:#1F497D">Rate our service with the Library & eLearning Survey</span></b><span lang="EN-GB" style="color:black"><o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB" style="font-size:10.0pt;font-family:"Tahoma",sans-serif;color:#1F497D">For Students:
<a href="http://library.hull-college.ac.uk/survey" target="_blank">http://library.hull-college.ac.uk/survey</a>
</span><span lang="EN-GB" style="color:black"><o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB" style="font-size:10.0pt;font-family:"Tahoma",sans-serif;color:#1F497D">For Staff:
<a href="http://library.hull-college.ac.uk/staffsurvey" target="_blank">http://library.hull-college.ac.uk/staffsurvey</a>
</span><span lang="EN-GB" style="color:black"><o:p></o:p></span></p>
</div>
<p class="MsoNormal"><span lang="EN-GB" style="color:#1F497D"> </span><span lang="EN-GB" style="color:black"><o:p></o:p></span></p>
<div>
<div style="border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal" style="margin-left:.5in"><b><span style="font-size:10.0pt;font-family:"Tahoma",sans-serif;color:black">From:</span></b><span style="font-size:10.0pt;font-family:"Tahoma",sans-serif;color:black">
<a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a> [<a href="mailto:users-bounces@shibboleth.net">mailto:users-bounces@shibboleth.net</a>]
<b>On Behalf Of </b>Arnal, Pascal<br>
<b>Sent:</b> 03 March 2015 16:14<br>
<b>To:</b> <a href="mailto:users@shibboleth.net">users@shibboleth.net</a><br>
<b>Subject:</b> Kerberos Authentication</span><span lang="EN-GB" style="color:black"><o:p></o:p></span></p>
</div>
</div>
<p class="MsoNormal" style="margin-left:.5in"><span lang="EN-GB" style="color:black"> <o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:.5in"><span lang="FR-CA" style="color:black">Hi,</span><span lang="EN-GB" style="color:black"><o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:.5in"><span lang="FR-CA" style="color:black"> </span><span lang="EN-GB" style="color:black"><o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:.5in"><span lang="EN-CA" style="color:black">I would like to use my Windows Authentication with Shibboleth IDP V3 AND Shibboleth SP V2.</span><span lang="EN-GB" style="color:black"><o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:.5in"><span lang="EN-CA" style="color:black">I followed the documentation
<a href="https://wiki.shibboleth.net/confluence/display/IDP30/KerberosAuthnConfiguration" target="_blank">
https://wiki.shibboleth.net/confluence/display/IDP30/KerberosAuthnConfiguration</a></span><span lang="EN-GB" style="color:black"><o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:.5in"><span lang="EN-CA" style="color:black">When I want to access my application, the login page of the IDP is displayed and after I filled my credentials, my application is accessible.</span><span lang="EN-GB" style="color:black"><o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:.5in"><span lang="EN-CA" style="color:black">Now I would like to use my Windows Authentication and the Kerberos Token for not fill again my credential.</span><span lang="EN-GB" style="color:black"><o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:.5in"><span lang="EN-CA" style="color:black"> </span><span lang="EN-GB" style="color:black"><o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:.5in"><span lang="EN-CA" style="color:black">Is-it possible, and how please ?</span><span lang="EN-GB" style="color:black"><o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:.5in"><span lang="EN-CA" style="color:black"> </span><span lang="EN-GB" style="color:black"><o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:.5in"><span lang="EN-CA" style="color:black">Thanks</span><span lang="EN-GB" style="color:black"><o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:.5in"><span lang="FR-CA" style="font-size:12.0pt;font-family:"Times New Roman",serif;color:black"> </span><span lang="EN-GB" style="color:black"><o:p></o:p></span></p>
<div style="margin-left:.5in">
<div class="MsoNormal" align="center" style="text-align:center"><span lang="FR-CA" style="font-size:12.0pt;font-family:"Times New Roman",serif;color:black">
<hr size="2" width="100%" align="center">
</span></div>
</div>
<p class="MsoNormal" style="margin-left:.5in"><span lang="FR-CA" style="font-size:7.5pt;font-family:"Arial",sans-serif;color:gray">AVIS: Ce courriel privilégié et confidentiel est destiné à la seule personne ou entité à laquelle il est adressé. Pour toute autre
personne, toute action prise en rapport à ce courriel ainsi que toute lecture, reproduction, transmission et/ou divulgation d'une partie ou de l'ensemble de celui-ci est interdite. Si vous n'êtes pas la personne autorisée à recevoir ce courriel, S.V.P. le
retourner à l'expéditeur et le détruire. Bien que ce courriel ait été traité contre les virus, il est de la responsabilité du destinataire de s'assurer que l'envoi en est exempt. Nos communications avec vous peuvent contenir des renseignements confidentiels
ou protégés par le secret professionnel. Si vous désirez que nous communiquions avec vous par un autre moyen de transmission que le courrier électronique ordinaire non sécurisé, veuillez nous en aviser.<br>
<br>
NOTICE: This privileged and confidential email is intended only for the individual or entity to whom it is addressed. With regard to all others, any action related with this email as well as any reading, reproduction, transmission and/or dissemination in whole
or in part of the information included in this email is prohibited. If you are not the addressee, immediately return the email to sender prior to destroying all copies. Even if this email is believed to be free from any virus, it is the responsibility of the
recipient to make sure that it is virus exempt. Our communications to you may contain confidential information or information protected under solicitor-client privilege. Please advise if you wish us to use a mode of communication other than regular, unsecured
e-mail in our communications with you.</span><span lang="EN-GB" style="color:black"><o:p></o:p></span></p>
</div>
<div>
<div class="MsoNormal" align="center" style="text-align:center"><span lang="EN-GB" style="font-size:12.0pt;font-family:"Times New Roman",serif;color:black">
<hr size="2" width="100%" align="center">
</span></div>
</div>
<div>
<p class="MsoNormal"><span lang="EN-GB" style="font-size:10.0pt;font-family:"Arial",sans-serif;color:#999999">This message is sent in confidence for the addressee only. It may contain confidential or sensitive information. The contents are not to be disclosed to
anyone other than the addressee. Unauthorised recipients are requested to preserve this confidentiality and to advise us of any errors in transmission. Any views expressed in this message are solely the views of the individual and do not represent the views
of the College. Nothing in this message should be construed as creating a contract.</span><span lang="EN-GB" style="font-size:12.0pt;font-family:"Times New Roman",serif;color:black"><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span lang="EN-GB" style="font-size:12.0pt;font-family:"Times New Roman",serif;color:black"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span lang="EN-GB" style="font-size:10.0pt;font-family:"Arial",sans-serif;color:#999999">Hull College owns the email infrastructure, including the contents.</span><span lang="EN-GB" style="font-size:12.0pt;font-family:"Times New Roman",serif;color:black"><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span lang="EN-GB" style="font-size:12.0pt;font-family:"Times New Roman",serif;color:black"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span lang="EN-GB" style="font-size:10.0pt;font-family:"Arial",sans-serif;color:#00CC33">Hull College is committed to sustainability, please reflect before printing this email.</span><span lang="EN-GB" style="font-size:12.0pt;font-family:"Times New Roman",serif;color:black"><o:p></o:p></span></p>
</div>
<div>
<div class="MsoNormal" align="center" style="text-align:center"><span lang="EN-GB" style="font-size:12.0pt;font-family:"Times New Roman",serif;color:black">
<hr size="2" width="100%" align="center">
</span></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</body>
</html>