<div dir="ltr"><div><br></div><div><br></div><div><br></div><div> <br><div class="gmail_extra"><br><div class="gmail_quote">On Mon, May 4, 2015 at 5:48 PM, Peter Schober <span dir="ltr"><<a href="mailto:peter.schober@univie.ac.at" target="_blank">peter.schober@univie.ac.at</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);border-left-style:solid;padding-left:1ex">* Surinaidu Majji <<a href="mailto:pioneer.suri@gmail.com">pioneer.suri@gmail.com</a>> [2015-05-04 08:12]:<br>
<span class="">> We have a "Third Party" which will have its own database and authentication<br>
> service. Because of the following components i am assuming the 3rd party as<br>
> one more "IDP" like shibboleth Idp.<br>
> 1) "Third Party" will give its own "login.jsp" if the user accessed the<br>
> application is not authenticated.<br>
> 2) It has its own database to authenticate the credentials entered in the<br>
> login page.<br>
> 3) It will give the "Token" and required user information once the user is<br>
> authenticated at Database.<br>
> 4) The token will be stored at application side(SP) to identify the user<br>
> when he access the application second time without going to Third Party idp.<br>
><br>
> That's why i am calling "Third Party" as an "IDP" which is similar to<br>
> Shibboleth Idp. Is my assumption correct? Please correct me if i am wrong.<br>
<br>
</span>There should be no guesswork involved (so I won't guess).<br>
Whether the third party deploys a SAML IDP or not (i.e., whether<br>
they're able to send SAML response messages to SAML request messages)<br>
is something you would ask them.<br></blockquote><div> - - We know the 3rd party will not support any SAML format. So I think they will not send SAML responses. They will only accept requests with in the XML format. If we say "3rd party" as an IDP then only i can use discovery service from shibboleth. Please give a brief idea about this. </div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);border-left-style:solid;padding-left:1ex">
<span class=""><br>
> If the third party is confimed as an IDP, Can i use "discover service" to<br>
> integrate "Third Party" in the existing application(Shibboleth SSO)<br>
> If i have to use the "discover service" to discover Idp(shibboleth or Third<br>
> party), What is the main purpose of using "discovery Service", except<br>
> finding which Idp it should redirects to authenticate.If it is the case, we<br>
> can write our own discovery service, why to use shibboleth discovery?Please<br>
> confirm my understanding.<br>
<br>
</span>Yes, to basically everything above. You could use one of the provided<br>
discovery services, or roll your own. The discovery services provided<br>
by the Shibboleth project are designed to deal with thousands of IDPs<br>
in a scalable way (if needed), which is not your issue here.<br>
<br>
For just 2 IDPs you could even create static links pointing to each<br>
IDP, initiating the desired protocol exchange via whatever method your<br>
SP (or IDPs) support.<br>
Since the SP is not Shibboleth we can't really be more specific here,<br>
of course.<br>
<span class=""><br></span></blockquote><div> - As per our current requirement we need to work with only 2 idp's, May be in the future it might be extended to one more.</div><div>I went through all the discovery services provided by shibboleth, I have the following observations.</div><div> a) Embede discovery service which is will be hosted on the server along with the SP. It suits for us but "Strongly recommanded to use Shibboleth SP", So we have our own SP.</div><div> b) Centralized discovery service which is for federation level which will be hosted on the different place, but here we only use 2 idp's that to in the same organization.</div><div><br></div><div>By above observations, We are thinking that we can not use shibboleth discovery service, Please let me know your suggestion on this. </div><div><br></div> initiating the desired protocol exchange via whatever method your<br><div>SP (or IDPs) support. </div><div>What is meant by protocol exchange here? </div><div> </div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);border-left-style:solid;padding-left:1ex"><span class="">
> - If "third Party" is not considered as an Idp" how to integrate<br>
> third party in our current application.<br>
<br>
</span>E.g. by having the organization responsible turn it into a SAML IDP<br>
(so that you can keep relying on SAML for the protection of your<br>
resources).<br>
Or by extending your resource/application to also support whatever<br>
(possibly home-grown) protocols the third party does support.<br>
I'd certainly strongly prefer one method over the other.<br></blockquote><div><br></div><div>- if the above is conformed as not an IDP, then only i can go for this option.</div><div> Here we will go with whatever</div>(possibly home-grown) protocols the third party does support.<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);border-left-style:solid;padding-left:1ex">
<span class=""><font color="#888888">-peter<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</font></span></blockquote></div><br></div></div></div>