<html><head><meta http-equiv="Content-Type" content="text/html charset=utf-8"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">Using SATOSA as a proxy for a 1:n mapping is fairly straightforward. I have done it with rocketchat and external IDP discovery. This should work for similar user cases as well.<div class=""><br class=""></div><div class="">- Rainer<br class=""><div class=""><br class=""></div><div class=""><br class=""><div><blockquote type="cite" class=""><div class="">Am 15.11.2017 um 17:45 schrieb David Huebner <<a href="mailto:david.huebner@daasi.de" class="">david.huebner@daasi.de</a>>:</div><br class="Apple-interchange-newline"><div class="">
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" class="">
<div text="#000000" bgcolor="#FFFFFF" class="">
<tt class="">Hi,</tt><tt class=""><br class="">
</tt><tt class=""><br class="">
</tt><tt class="">should be doable with the nextcloud SSO & SAML app [1].</tt><tt class=""><br class="">
</tt><tt class="">The SAML2 plugin there is only able to auth-n against a
single IdP, but apparently you can also use environment variables.</tt><tt class=""><br class="">
</tt><tt class=""><br class="">
</tt><tt class="">So basically, protect everything with Apache &
Shibboleth SP, set REMOTE_USER accordingly and use it in
nextcloud.</tt><tt class=""><br class="">
</tt><tt class=""><br class="">
</tt><tt class="">The documentation mentions this near the end.</tt><tt class=""><br class="">
</tt><tt class=""><br class="">
</tt><tt class="">I can't confirm that it works, since we are only running
the plugin against one IdP, but I don't see why it shouldn't.</tt><tt class=""><br class="">
</tt><tt class=""><br class="">
</tt><tt class="">- David</tt><tt class=""><br class="">
</tt><tt class=""><br class="">
</tt><tt class="">[1]:
<a class="moz-txt-link-freetext" href="https://docs.nextcloud.com/server/12/admin_manual/configuration_server/sso_configuration.html">https://docs.nextcloud.com/server/12/admin_manual/configuration_server/sso_configuration.html</a></tt><tt class=""><br class="">
</tt><tt class=""><br class="">
</tt>
<div class="moz-cite-prefix"><tt class="">On 15.11.2017 17:24, Pablo Escobar
Lopez wrote:</tt><tt class=""><br class="">
</tt></div>
<blockquote type="cite" cite="mid:CANKY03WRBu14xoTHLX2aLv+ZjGmhoC9kjr5bBczTCL8PdYNg1A@mail.gmail.com" class="">
<div dir="ltr" class=""><tt class="">Hi </tt>
<div class=""><tt class=""><br class="">
</tt></div>
<div class=""><tt class="">In our university we would like to deploy a
owncloud/nextcloud instance with shibboleth authentication
and support for multiple idps. We already have the SP
working. </tt></div>
<div class=""><tt class=""><br class="">
</tt></div>
<div class=""><tt class="">Can anyone confirm if this setup is possible? Is there
any documentation available about this specific topic?</tt></div>
<div class=""><tt class=""><br class="">
</tt></div>
<div class=""><tt class="">Thanks in advance for any help or advice.</tt></div>
<div class=""><tt class=""><br class="">
</tt></div>
<div class=""><tt class="">regards,</tt></div>
<div class=""><tt class="">Pablo.</tt></div>
<div class=""><tt class=""><br clear="all" class="">
</tt>
<div class=""><tt class=""><br class="">
</tt></div>
<tt class="">-- </tt><tt class=""><br class="">
</tt>
<div class="gmail_signature" data-smartmail="gmail_signature">
<div dir="ltr" class="">
<div class="">
<div dir="ltr" class="">
<div class="">
<div dir="ltr" class="">
<div class="">
<div dir="ltr" class="">
<div class="">
<div dir="ltr" class="">
<div class="">
<div dir="ltr" class="">
<div class="">
<div dir="ltr" class=""><tt class=""><span style="font-size:10.0pt" class="">Pablo
Escobar López<br class="">
HPC systems engineer<br class="">
sciCORE, University of Basel<br class="">
</span></tt><tt class=""><span style="font-size:12.8000001907349px" class="">SIB </span></tt><tt class="">Swiss
Institute of Bioinformatics</tt><tt class=""><span style="font-size:10.0pt" class=""><br class="">
<a href="http://scicore.unibas.ch/" target="_blank" moz-do-not-send="true" class="">http://scicore.unibas.ch</a><br class="">
</span></tt></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<tt class=""><br class="">
</tt>
<fieldset class="mimeAttachmentHeader"></fieldset>
<tt class=""><br class="">
</tt>
</blockquote>
<tt class=""><br class="">
</tt>
</div>
-- <br class="">For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" class="">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br class="">To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" class="">users-unsubscribe@shibboleth.net</a></div></blockquote></div><br class=""></div></div></body></html>