<html><head><meta http-equiv="Content-Type" content="text/html charset=utf-8"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">Besides OpenAM you may want to look into:<div class="">Midpoint <a href="https://evolveum.com/midpoint/" class="">https://evolveum.com/midpoint/</a></div><div class="">Syncope <a href="https://syncope.apache.org/" class="">https://syncope.apache.org/</a></div><div class=""><br class=""></div><div class="">- Rainer</div><div class=""><br class=""><div><blockquote type="cite" class=""><div class="">Am 14.04.2016 um 08:48 schrieb Shagun Akarsh <<a href="mailto:shagun.akarsh@wooqer.com" class="">shagun.akarsh@wooqer.com</a>>:</div><br class="Apple-interchange-newline"><div class=""><div dir="ltr" class=""><div class=""><div class="">Thanks Andy & Rod for prompt replies. <br class=""><br class=""></div>Can you suggest any open-source project that can be smoothly integrated for Identity Management with Shibboleth IdPv3. <br class=""><br class="">Has anyone used OpenAM Identity Management tool: <a href="https://www.forgerock.com/platform/identity-management/" class="">https://www.forgerock.com/platform/identity-management/</a>. Kindly suggest alternatives. <br class=""><br class=""></div>Thanks.<br class=""></div><div class="gmail_extra"><br class=""><div class="gmail_quote">On Wed, Apr 13, 2016 at 10:57 PM, Andrew Morgan <span dir="ltr" class=""><<a href="mailto:morgan@orst.edu" target="_blank" class="">morgan@orst.edu</a>></span> wrote:<br class=""><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Shagun,<br class="">
<br class="">
This is not a function of a SAML IDP or SP.  Updating user identity information is Identity Management.  The IDP handle authentication and attribute release.  It does not manage identity data.<br class="">
<br class="">
Read the second answer from that Stackoverflow link regarding SCIM. That's more relevant for your use case.<br class="">
<br class="">
        Andy<span class=""><br class="">
<br class="">
On Wed, 13 Apr 2016, Shagun Akarsh wrote:<br class="">
<br class="">
</span><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">
Yes all SPs are from within single domain. Also both IdP and SPs are<br class="">
internal to one organization but SPs are hosted across different<br class="">
datacenters.<br class="">
<br class="">
I will try to break down my problem statement:<br class="">
<br class="">
First, (Update/Add data on IdP's DB from SP after successful<br class="">
authentication) In an SP initiated SSO scenario, how can a user update<br class="">
his/her password (or any other field on IdP) ?<br class="">
<br class="">
Second, (Synching of user information across SPs) I want user's information<br class="">
to be updated across all SPs when it gets updated at IdP. I have a problem<br class="">
very similar to this (Kindly read comments on Vladimír Schäfer<br class=""></span>
<<a href="http://stackoverflow.com/users/3510410/vladim%c3%adr-sch%c3%a4fer" rel="noreferrer" target="_blank" class="">http://stackoverflow.com/users/3510410/vladim%c3%adr-sch%c3%a4fer</a>>'s<span class=""><br class="">
answer) :<br class="">
<a href="http://stackoverflow.com/questions/23567648/sso-how-to-synchronize-user-accounts-between-service-provider-and-identity-prov" rel="noreferrer" target="_blank" class="">http://stackoverflow.com/questions/23567648/sso-how-to-synchronize-user-accounts-between-service-provider-and-identity-prov</a><br class="">
<br class="">
<br class="">
On Wed, Apr 13, 2016 at 2:29 PM, Rod Widdowson <<a href="mailto:rdw@steadingsoftware.com" target="_blank" class="">rdw@steadingsoftware.com</a>><br class="">
wrote:<br class="">
<br class="">
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
which can be updated by any of the SP. Also we want to allow to update<br class="">
</blockquote>
user information from SPs.<br class="">
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<br class="">
Thus we want to write APIs on IdP for such updates which can be called<br class="">
</blockquote>
from SPs directly. How to implement this.<br class="">
<br class="">
Write it into a Database from the SP and uses RDBMSDataConnector on the<br class="">
IdP?  Or LDAP?<br class="">
<br class="">
This has to be internal to a single privacy/security domain I guess?<br class="">
Otherwise I don't even want to think about the privacy&secuirty<br class="">
implications...<br class="">
<br class="">
Rod<br class="">
<br class="">
--<br class="">
To unsubscribe from this list send an email to<br class="">
<a href="mailto:users-unsubscribe@shibboleth.net" target="_blank" class="">users-unsubscribe@shibboleth.net</a><br class="">
<br class="">
</blockquote>
<br class="">
<br class="">
<br class="">
-- <br class="">
Shagun Akarsh<br class="">
Ph: +91-9902095371<br class="">
Research Engineer<br class="">
Wooqer Labs,<br class="">
Bangalore.<br class="">
</span></blockquote>
<br class="">--<br class="">
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" class="">users-unsubscribe@shibboleth.net</a><br class=""></blockquote></div><br class=""><br clear="all" class=""><br class="">-- <br class=""><div class="gmail_signature"><div dir="ltr" class=""><div class=""><div class="">Shagun Akarsh<br class=""></div>Ph: +91-9902095371<br class=""></div><div class="">Research Engineer<br class=""></div><div class="">Wooqer Labs,<br class="">Bangalore.<br class=""></div></div></div>
</div>
-- <br class="">To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" class="">users-unsubscribe@shibboleth.net</a></div></blockquote></div><br class=""></div></body></html>