Skip to Content.
Sympa Menu

shibboleth-dev - RE: SAML/shib 2 & authN referral

Subject: Shibboleth Developers

List archive

RE: SAML/shib 2 & authN referral


Chronological Thread 
  • From: "Scott Cantor" <>
  • To: <>
  • Subject: RE: SAML/shib 2 & authN referral
  • Date: Tue, 20 Jun 2006 11:43:20 -0400
  • Organization: The Ohio State University

> For the purposes of AuthN Proxying, will the versioning compatibility
> be the same as standard Shibboleth? (Shib 2.0 will work with 1.3, but
> no lower, if I remember correctly). Obviously the proxying IdP would
> need to talk SAML 2, but what about the authenticating IdP?

I can't answer that, really, since we haven't put proxying on the roadmap
list yet.

But I suspect that anything can be treated as "proxying". It's more a
question of how the IdP interprets the AuthnRequest and whether it inserts
an AuthenticatingAuthority into the AuthnStatement. In theory, that could be
configurable outside of the specifics of how the authentication got done. It
becomes a policy/deployment question as to what constitutes a separate IdP.

Passport, yes, local CAS, no. Something like that. Each handler gets to
decide.

-- Scott




Archive powered by MHonArc 2.6.16.

Top of Page