Skip to Content.
Sympa Menu

shibboleth-dev - Re: Sub: Web Portal + Shibboleth possibility ???

Subject: Shibboleth Developers

List archive

Re: Sub: Web Portal + Shibboleth possibility ???


Chronological Thread 
  • From: "Venkata Krishna Ravula" <>
  • To:
  • Subject: Re: Sub: Web Portal + Shibboleth possibility ???
  • Date: Mon, 27 Nov 2006 04:54:07 -0600
  • Domainkey-signature: a=rsa-sha1; q=dns; c=nofws; s=beta; d=gmail.com; h=received:message-id:date:from:to:subject:in-reply-to:mime-version:content-type:references; b=jdPDsa8vvRKnOsJu5qrgRk4DcsKGDCGu8sgOKcYNO3O554gVC+/ac1fugGBjKdypSaLCappnOTJwOgKEHC2L6ukg4wvAuvHuEO/hDwRiKLN22axkzZ7viDdLmgKxf0z74gqNdXkVl+yzaIEoc/uPOQHvvRolXhidsYg0EdWbq4o=

Dear Tom and Nate,
 
                 Appreciate your response. Just like Nate suggested I am looking into MAMS. Portal talks to Shibboleth and even the API is available. Now I guess the whole question is to make the portal once authenticated with proper credentials to be trusted by the Globus tool kit. This is where the entire scenario revolves. How to make the portal to be trusted by the GTK after authenticated by Shibboleth ? Any suggestions would be greatly appreciated.
 
Thank you
 
Regards
 
Venkat
 
On 11/16/06, Tom Scavo <> wrote:
On 11/16/06, Venkata Krishna Ravula < > wrote:
>
>                         A web portal communicates with the Shibboleth server
> to authenticate a user. Then the Globus tool Kit trusts the portal and then
> any service later requested by the user be provided by the Globus Tool kit
> becauses it now trusts the portal.

Yes, grid communities are doing this today.  OGCE does this, for
example.  What's missing in today's deployments, however, is access
control.

We are currently working on a project that would push attributes to
Globus Toolkit by binding SAML attribute assertions to X.509 proxy
certificates.  This wiki page gives the general idea:

https://authdev.it.ohio-state.edu/twiki/bin/view/GridShib/ScienceGateway

Note that the Portal/Gateway need not be shib-enabled.  If it *is*
shib-enabled (Nate gave a pointer), the authentication context from
the shib-issued SSO assertion may be pushed to Globus Toolkit along
with attributes.  This raises some interesting questions with respect
to attribute aggregation (which Nate can tell you more about :).

Hope this helps,
Tom




Archive powered by MHonArc 2.6.16.

Top of Page