Skip to Content.
Sympa Menu

grouper-users - [grouper-users] RE: Grouper Web Services Authentication

Subject: Grouper Users - Open Discussion List

List archive

[grouper-users] RE: Grouper Web Services Authentication


Chronological Thread 
  • From: Chris Hyzer <>
  • To: "Klug, Lawrence" <>, "" <>
  • Subject: [grouper-users] RE: Grouper Web Services Authentication
  • Date: Wed, 9 May 2012 15:16:42 +0000
  • Accept-language: en-US

I assume you saw this wiki already?

 

https://spaces.internet2.edu/display/Grouper/Authentication+for+Grouper+Web+Services#AuthenticationforGrouperWebServices-Rampart&nsp;

 

Also, this is mentioned in the admin grouper ws training video J

 

http://www.youtube.com/watch?v=E7ScEVUHvfM

https://spaces.internet2.edu/display/Grouper/Grouper+Training

 

If you need more info let me know…

 

Thanks,

Chris

 

From: Klug, Lawrence [mailto:]
Sent: Tuesday, May 08, 2012 6:23 PM
To: Chris Hyzer;
Subject: RE: Grouper Web Services Authentication

 

Hi Chris,

 

How do we configure Grouper WS for rampart?  Is there a switch somewhere?

 

Thanks,

 

Lawrence

 

From: Chris Hyzer []
Sent: Monday, May 07, 2012 11:17 AM
To: Klug, Lawrence;
Subject: RE: Grouper Web Services Authentication

 

The authn is pluggable, I don’t think there is an ED plugin (if someone has one let us know), we could write one pretty easily…

 

Chris

 

From: Klug, Lawrence
Sent: Monday, May 07, 2012 2:13 PM
To: Chris Hyzer;
Subject: RE: Grouper Web Services Authentication

 

>>>How do you authenticate other web services at your institution?

 

I’m trying to find out what the other web services use.  We have a an ED web service for the Enterprise Directory.  We have a  Kerberos server for user/pass -- all the other user info is in the ED, so it sounds similar to your setup.

 

Thanks,

 

Lawrence

 

From: Chris Hyzer []
Sent: Monday, May 07, 2012 10:35 AM
To: Klug, Lawrence;
Subject: RE: Grouper Web Services Authentication

 

You could do web server or app server authn… e.g. apache user/pass file, or tomcat-users.xml.  At Penn we use Kerberos service principal user/pass in the http basic auth section, and Grouper will authenticate against the kdc.  This is nice since the developer at the school/center can have their kadmin create and maintain the service principal/pass.  With either of these you need another source to keep the user names (if they don’t fit in an existing source).  I think you can also do this with Grouper 2.1 local entities.  How do you authenticate other web services at your institution?

 

Thanks,

Chris

 

From: On Behalf Of Klug, Lawrence
Sent: Monday, May 07, 2012 1:14 PM
To:
Subject: [grouper-users] Grouper Web Services Authentication

 

What is the recommended best practice for Grouper Web Services Authentication?  I’ve looked over the available documentation, but it’s not clear to me how to proceed.

 

Thanks,

 

Lawrence Klug

IMS Platform Development

310 825-2061

ext 52061

 




Archive powered by MHonArc 2.6.16.

Top of Page