Skip to Content.
Sympa Menu

shibboleth-dev - RE: Shibboleth CAS LDAP Kerberos

Subject: Shibboleth Developers

List archive

RE: Shibboleth CAS LDAP Kerberos


Chronological Thread 
  • From: "Lisa Tan" <>
  • To: <>
  • Subject: RE: Shibboleth CAS LDAP Kerberos
  • Date: Wed, 6 Jun 2007 15:33:43 -0400

Am I correct that Shibboleth itself can do SSO? If yes, I should be able to
configure Shibboleth directly against LDAP, right?

Thanks,

-----Original Message-----
From: Scott Cantor
[mailto:]

Sent: Wednesday, June 06, 2007 12:50 PM
To:

Subject: Re: Shibboleth CAS LDAP Kerberos

Lisa Tan wrote:
> I like to configure Shibboleth against LDAP to get attributes from our
LDAP.
> If my understanding is correct, I don't have to use CAS or Kerberos to
> handler the authentication. Could anyone provide some insights about the
> benefits of using CAS or Kerberos and the documentation to configure them?

I think it would be accurate to say that that decision really has to be
made independent of Shibboleth. You don't start with Shibboleth and then
say "how should I authenticate users"? It's the other way around, you
have to decide on the right strategy for authentication based on your
needs. Shibboleth will just use whatever you pick.

You might want to take a look at the authentication roadmap document
that NMI produced:

http://www.nmi-edit.org/roadmap/draft-authn-roadmap-03/

Some of the material from the CAMP might be useful also:

http://www.educause.edu/camp071

-- Scott





Archive powered by MHonArc 2.6.16.

Top of Page