<div dir="ltr">I just did our AdAstra integration, which just involved telling them which SAML attribute to use to map the username on their side. They are in InCommon; we are in InCommon. It all worked as federation is supposed to.<div><br></div><div> -paul </div></div><div class="gmail_extra"><br clear="all"><div><div class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div>-- </div><div>Paul Engle</div><div>Office of Information Technology</div><div><a href="mailto:pengle@rice.edu" target="_blank">pengle@rice.edu</a></div><div>713-348-4702</div></div></div></div>
<br><div class="gmail_quote">On Wed, Mar 28, 2018 at 1:30 PM, Corey Scholefield <span dir="ltr"><<a href="mailto:coreys@uvic.ca" target="_blank">coreys@uvic.ca</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div bgcolor="white" lang="EN-US" link="#0563C1" vlink="#954F72">
<div class="m_1366261959697992764WordSection1">
<p class="MsoNormal"><span style="font-size:14.0pt">Great question!<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:14.0pt"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:14.0pt">We have a fairly simple decision tree that favours SAML via Shib IdP for all vended cloud-services, if the vendor supports it.<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:14.0pt"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:14.0pt">A recent wrinkle we have noted is the degree of support for application logout capability that the vendor supports. At this point, we’ve noticed that some vendors have invested more effort in their CAS-based
logout, over a SAML-logout.<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:14.0pt"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:14.0pt">Corey S.<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:16.0pt"><u></u> <u></u></span></p>
<div>
<table class="m_1366261959697992764MsoNormalTable" border="0" cellspacing="0" cellpadding="0" style="border-collapse:collapse">
<tbody>
<tr>
<td width="92" valign="top" style="width:69.0pt;padding:0cm 5.4pt 0cm 5.4pt">
<p class="MsoNormal"><span style="font-size:14.0pt;font-family:Calibri"><img width="125" height="133" id="m_1366261959697992764_x0000_i1025" src="cid:image001.jpg@01D3C688.2E6E7880" alt="id:image001.jpg@01D337AD.F8BD9400"></span><span style="font-size:14.0pt;font-family:Calibri"><u></u><u></u></span></p>
</td>
<td width="396" valign="top" style="width:297.0pt;padding:0cm 5.4pt 0cm 5.4pt">
<p class="MsoNormal"><span style="font-size:14.0pt;font-family:Calibri">Corey Scholefield<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:14.0pt;font-family:Calibri">Team Lead, Identity Services<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:14.0pt;font-family:Calibri">University Systems<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:14.0pt;font-family:Calibri"><a href="http://www.uvic.ca/" target="_blank"><span style="color:#0563c1">University of Victoria</span></a><u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:14.0pt;font-family:Calibri">T 250-472-4549<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:14.0pt;font-family:Calibri">C 250-812-4861<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:14.0pt;font-family:Calibri"><a href="mailto:coreys@uvic.ca" target="_blank">coreys@uvic.ca</a><u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:14.0pt;font-family:Calibri"><a href="https://www.uvic.ca/systems" target="_blank">https://www.uvic.ca/systems</a><u></u><u></u></span></p>
</td>
</tr>
</tbody>
</table>
</div>
<p class="MsoNormal"><span style="font-size:16.0pt"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:16.0pt"><u></u> <u></u></span></p>
<div style="border:none;border-top:solid #b5c4df 1.0pt;padding:3.0pt 0cm 0cm 0cm">
<p class="MsoNormal"><b><span style="font-family:Calibri;color:black">From: </span>
</b><span style="font-family:Calibri;color:black">users <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a>> on behalf of IAM David Bantz <<a href="mailto:dabantz@alaska.edu" target="_blank">dabantz@alaska.edu</a>><br>
<b>Reply-To: </b>Shib Users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br>
<b>Date: </b>Wednesday, March 28, 2018 at 10:57 AM<br>
<b>To: </b>Shib Users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br>
<b>Subject: </b>Service owner's question CAS or Shibboleth<u></u><u></u></span></p>
</div><div><div class="h5">
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">UA service owner for new vended cloud service that supports authN via CAS or Shibboleth (Ad Astra) asks for input on selecting one or the other, as we still run separate CAS (mainly for Banner) and Shibboleth identity services (tied to
same identities in AD). <u></u><u></u></p>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">Can anyone share a simple list of +/- for responding to this question?<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">Or know specific reason to implement one or the other for Ad Astra?<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">David Bantz<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">UA OIT IAM<u></u><u></u></p>
</div>
</div>
</div></div></div>
</div>
<br>--<br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/<wbr>confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br></blockquote></div><br></div>