<html><head><meta http-equiv="content-type" content="text/html; charset=utf-8"></head><body dir="auto"><div>We've set up a proof of concept using Shib, and hope to complete that work early this fall. We only worked through the most basic authentication before having to divert energies to other upgrades.</div><div><br></div><div>The only gotcha so far has been that the Banner products (running through WebLogic) were determined to perform SSL v2 HELLOs, which our Shib server rejects. It took a little while to diagnose that and then fix up WebLogic's crypto. </div><div><br></div><div>Internally, Ellucian staff appear to be on a dozen different pages regarding SAML and Shib support and configuration. I hope that is beginning to improve...</div><div><br></div><div>-- Jorj</div><div><br><div>Sent from my iPhone</div></div><div><br>On Aug 15, 2016, at 18:18, IAM David Bantz <<a href="mailto:dabantz@alaska.edu">dabantz@alaska.edu</a>> wrote:<br><br></div><blockquote type="cite"><div><meta http-equiv="Content-Type" content="text/html; charset=utf-8"><div dir="ltr">Our ERP manager called attention to Ellucian's documentation indicating Banner 9.x can support SAML authentication rather than CAS. There' seems to be quite a caveat for Shibboleth IdP users though:<div><br></div><div>
                
        
        
                <div class="" title="Page 37">
                        <div class="">
                                <div class="">
                                        <blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><span style="font-size:10pt;font-family:Arial">You can... change the configuration of Banner Admin Pages after deployment to
use the SAML protocol for user authentication with EIS as the authentication server.<br>
</span><span style="font-size:10pt;font-family:"Arial,Bold"">Note: </span><span style="font-size:10pt;font-family:Arial">If you are using an authentication server other than EIS, you must
adapt these instructions accordingly. </span></blockquote><div><br></div><div>We currently protect Banner and Banner-integrated apps with CAS.</div><div><br></div><div>Are there institutions or individuals on this list who:<br></div><div><br></div><div>(a) have made a written value / benefit calculation of switching Banner login from CAS to SAML in 9.x using Shibboleth IdP ? and/or</div><div><br></div><div>(b) worked through what "adaptations" of the instructions are necessary for use of Shibboleth IdP (rather than EIS) ?</div><div><br></div><div>and are willing to share them?</div><div><br></div><div>David Bantz</div>
                                        
                                </div>
                        </div>
                </div></div></div>
</div></blockquote><blockquote type="cite"><div><span>-- </span><br><span>To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a></span></div></blockquote></body></html>