Skip to Content.
Sympa Menu

shibboleth-dev - Re: Shibboleth OSID

Subject: Shibboleth Developers

List archive

Re: Shibboleth OSID


Chronological Thread 
  • From:
  • To:
  • Subject: Re: Shibboleth OSID
  • Date: Wed, 16 Nov 2005 13:20:58 -0500

At 11:58 AM -0500 11/16/05, Tom Scavo wrote:
Hmm, if you google "shibboleth authn osid", you get all kinds of
interesting hits, including this at the top:

http://stc.cis.brown.edu/~stc/Projects/LionShare/Docs/LS-OKI.html


the LionShare project at psu is funded by the Mellon Foundation, which also funded development of the OKI standards. Mellon was very interested in having LS explore the use of the OSIDs (this shouldn't be a surprise to anyone...).

However, the LS project concluded early on that some of the OSIDs weren't really useable in a client-server environment. They were designed for a single container environment (eg an LMS running within a servlet container); they were not designed for use by both a client and a server in a distributed environment. An OSID in that container could certainly communicate with a remote environment. But that's different from a client using an Authn OSID to somehow "authenticate" to a remote service, and have the Authn OSID use an existing TCP connection to that service, and have the Authn OSID help to appropriately insert authn credentials within some other protocol stream (think authenticating to a remote SQL server, or using SASL, etc).

It remains a dream.....

Will-- can you provide a bit more detail about your specific situation?



Archive powered by MHonArc 2.6.16.

Top of Page