Skip to Content.
Sympa Menu

shibboleth-dev - Re: authentication authority

Subject: Shibboleth Developers

List archive

Re: authentication authority


Chronological Thread 
  • From: Tom Scavo <>
  • To: Scott Cantor <>
  • Cc:
  • Subject: Re: authentication authority
  • Date: Thu, 13 Oct 2005 18:13:32 -0400
  • Domainkey-signature: a=rsa-sha1; q=dns; c=nofws; s=beta; d=gmail.com; h=received:message-id:date:from:to:subject:cc:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references; b=rc3yHoZhO/n7xfrdEXB+SufldtEDbtnobRKzHS1ONhEAhIoZexCSWI5RuAuBHUntS+w7P/+wQ4MS7/KPR82dCGdo0X+IUEzRkQ9l0pvLBb13w2r3OUXvibWgYDwHrqKJ609A4VM5fmIAnkpqJXxRDywV4XaO91GaJ/Kqb/J5k4M=

On 10/13/05, Scott Cantor
<>
wrote:
> > 1) A MyProxy Client, on behalf of the Grid User, sends a MyProxy
> > Protocol request to the MyProxy Server. The Grid User's
> > authentication credentials (username/password) are included with the
> > request.
>
> What does this protocol consist of?

You don't want to know... ;-)

> I just wonder
> if it isn't better to do what I originally suggested, use a SAML assertion
> issued by the IdP to authenticate to the MyProxy service. That of course
> also gets you a subject identifier for the cert that will be valid at the
> AA.

Excellent idea! I'll look at that more closely and see what the issues are.

> One thing to note here...this all works more or less fine but *only* because
> we actually have a bit of a long-standing bug in that we don't really issue
> transient IDs to specific SPs. So there's no SP check made when a query
> comes in. Really there should be.

Good point. This anticipates a question Tom Barton had on the
GridShib call today. Thanks for mentioning this.

Scott, your comments and suggestions continue to be invaluable.
Thanks for taking the time.

Tom



Archive powered by MHonArc 2.6.16.

Top of Page