shibboleth-dev - Re: authentication authority
Subject: Shibboleth Developers
List archive
- From: Tom Scavo <>
- To: Scott Cantor <>
- Cc:
- Subject: Re: authentication authority
- Date: Fri, 14 Oct 2005 13:20:25 -0400
- Domainkey-signature: a=rsa-sha1; q=dns; c=nofws; s=beta; d=gmail.com; h=received:message-id:date:from:to:subject:cc:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references; b=BTF81/Ite7unNlTey6JbLw8SAd5fSVOJYgqDOzXpwgRLMA1uP037iPUUZk9HV7lOjjHP/+QAJ9dCFk5r5I0sIrN/UFfmtaP83OXRHVOrvYxEr5ixNwoqFqms570uQxgbyOUdVSKsN9PasoN/sFJ+QEz5cL5y+JcKTAn7MbjZH7w=
On 10/13/05, Tom Scavo
<>
wrote:
> On 10/13/05, Scott Cantor
> <>
> wrote:
>
> > I just wonder
> > if it isn't better to do what I originally suggested, use a SAML assertion
> > issued by the IdP to authenticate to the MyProxy service. That of course
> > also gets you a subject identifier for the cert that will be valid at the
> > AA.
>
> Excellent idea! I'll look at that more closely and see what the issues are.
I've gone over this thread numerous times but unfortunately I have
absolutely no idea how to implement this step:
> 1 Grid Client authenticates to SSO service (means unspecified)
Certainly you don't mean the current SSO service, which as we all know
is geared towards browser users. I just don't know how a command-line
MyProxy Client can obtain a SAML authN assertion, from an existing
Shib component or otherwise.
We have a grid portal use case in the back of our minds, and we're
paying close attention to the delegation protocol you posted recently
(even if we are mired in SAML 1.1) but that is mostly irrelevant for
our non-browser use case AFAICT.
Thanks,
Tom
- Re: authentication authority, (continued)
- Re: authentication authority, Chad La Joie, 10/07/2005
- Re: authentication authority, Von Welch, 10/09/2005
- Re: authentication authority, Tom Scavo, 10/08/2005
- Re: authentication authority, Scott Cantor, 10/08/2005
- Re: authentication authority, Tom Scavo, 10/10/2005
- RE: authentication authority, Scott Cantor, 10/10/2005
- Re: authentication authority, Tom Scavo, 10/12/2005
- RE: authentication authority, Scott Cantor, 10/13/2005
- Re: authentication authority, Tom Scavo, 10/13/2005
- Re: authentication authority, Scott Cantor, 10/13/2005
- Re: authentication authority, Tom Scavo, 10/14/2005
- Re: authentication authority, Brent Putman, 10/14/2005
- Re: authentication authority, Tom Scavo, 10/14/2005
- Re: authentication authority, Brent Putman, 10/14/2005
- Re: authentication authority, Tom Scavo, 10/14/2005
- Re: authentication authority, Tom Barton, 10/14/2005
- Re: authentication authority, Tom Scavo, 10/14/2005
- RE: authentication authority, Scott Cantor, 10/14/2005
- Re: authentication authority, Tom Scavo, 10/14/2005
- Re: authentication authority, Scott Cantor, 10/14/2005
- Re: authentication authority, Brent Putman, 10/14/2005
Archive powered by MHonArc 2.6.16.