Skip to Content.
Sympa Menu

shibboleth-dev - Re: wrt user entry of a pointer to their IDP ..or.. "invisible SSO"

Subject: Shibboleth Developers

List archive

Re: wrt user entry of a pointer to their IDP ..or.. "invisible SSO"


Chronological Thread 
  • From: Jeff Hodges <>
  • To:
  • Subject: Re: wrt user entry of a pointer to their IDP ..or.. "invisible SSO"
  • Date: Wed, 12 Sep 2007 10:04:40 -0700

Josh Howlett wrote:
>
> The first work item is 'unified Single Sign On' (uSSO). This uses
> EAP-based network authentication (for example, over PPP, PPPoA, PPPoE,
> IEEE 802.1X, IEEE 802.11i etc) to (1) transparently sign the user into
> their IdP and (2) establish a discovery context with a WAYF or Discovery
> Service. I have a draft spec in case anyone is curious and some interest
> from a couple of vendors in implementing it.

I'm curious about seeing the spec, thanks.


> While uSSO mitigates some of the 'user experience' problems associated
> with sign-on and discovery, I regard it more as a work-around rather
> than a proper fix, which I believe necessitates a new Web SSO profile
> that incorporates discovery explicitly. I have some rough ideas as to
> how Kerberos might be used to realise this.

for the vanila-browser case?

=JeffH




Archive powered by MHonArc 2.6.16.

Top of Page