Skip to Content.
Sympa Menu

shibboleth-dev - Re: authentication authority

Subject: Shibboleth Developers

List archive

Re: authentication authority


Chronological Thread 
  • From: Tom Scavo <>
  • To: Scott Cantor <>
  • Cc:
  • Subject: Re: authentication authority
  • Date: Fri, 14 Oct 2005 13:20:25 -0400
  • Domainkey-signature: a=rsa-sha1; q=dns; c=nofws; s=beta; d=gmail.com; h=received:message-id:date:from:to:subject:cc:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references; b=BTF81/Ite7unNlTey6JbLw8SAd5fSVOJYgqDOzXpwgRLMA1uP037iPUUZk9HV7lOjjHP/+QAJ9dCFk5r5I0sIrN/UFfmtaP83OXRHVOrvYxEr5ixNwoqFqms570uQxgbyOUdVSKsN9PasoN/sFJ+QEz5cL5y+JcKTAn7MbjZH7w=

On 10/13/05, Tom Scavo
<>
wrote:
> On 10/13/05, Scott Cantor
> <>
> wrote:
>
> > I just wonder
> > if it isn't better to do what I originally suggested, use a SAML assertion
> > issued by the IdP to authenticate to the MyProxy service. That of course
> > also gets you a subject identifier for the cert that will be valid at the
> > AA.
>
> Excellent idea! I'll look at that more closely and see what the issues are.

I've gone over this thread numerous times but unfortunately I have
absolutely no idea how to implement this step:

> 1 Grid Client authenticates to SSO service (means unspecified)

Certainly you don't mean the current SSO service, which as we all know
is geared towards browser users. I just don't know how a command-line
MyProxy Client can obtain a SAML authN assertion, from an existing
Shib component or otherwise.

We have a grid portal use case in the back of our minds, and we're
paying close attention to the delegation protocol you posted recently
(even if we are mired in SAML 1.1) but that is mostly irrelevant for
our non-browser use case AFAICT.

Thanks,
Tom



Archive powered by MHonArc 2.6.16.

Top of Page