Skip to Content.
Sympa Menu

shibboleth-dev - Re: SHIB Status call -- 2/11/2008) -- 12:00 pm EDT, 9 am PDT

Subject: Shibboleth Developers

List archive

Re: SHIB Status call -- 2/11/2008) -- 12:00 pm EDT, 9 am PDT


Chronological Thread 
  • From: "Tom Scavo" <>
  • To:
  • Cc: "Ajay Daryanani" <>
  • Subject: Re: SHIB Status call -- 2/11/2008) -- 12:00 pm EDT, 9 am PDT
  • Date: Sun, 17 Feb 2008 19:28:48 -0500
  • Domainkey-signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=message-id:date:from:to:subject:cc:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references; b=mA6NHnpmQWCH2b5ogKsfXm8YHKyzYeoMemL3513NOSR0tezfvs+w0glxl95JChxCLYAkH87RHlDJyFxhsWVTbqvqh1WPlydosfFBO4Z5N5UPClIOXn4zkI86Im7uVYqf1XHJ2ItvZplDgNBSZCG9oAtt+x7Df5AB8Pxa27LxOp4=

Thanks, Diego. So then I'll ask the same question Steven asked awhile
ago :-) Is the code available for download and what is the license
attached to this code? I know some folks who are very anxious to have
a Java SP and this seems to be a good first step.

Many thanks,
Tom

On Feb 17, 2008 5:45 PM, Diego R. Lopez
<>
wrote:
>
> On 15 Feb 2008, at 22:09, Tom Scavo wrote:
>
> > Is the Shib 1.3 IdP involved in this exchange an ordinary IdP, or is
> > it extended to support the eduGAIN WebSSO profile in some way?
>
> This is what the eduGAIN profile says about WebSSO using SAML 1.1:
>
> > For those eduGAIN BEs configured to use SAML 1.1, Web SSO procedures
> > MUST comply with those described by the Shibboleth Web SSO Browser/
> > POST profile (as described in [SAMLBind] and [ShibArch]), and
> > according to the following rules:
> > · The providerId parameter used in the GET request to the H-BE
> > SHALL contain the unique identifier of the requesting R-BE. It MUST
> > be coded according to the structure defined for BE identifiers in
> > the guidelines of section 3.1.
> > · The SAML response sent by the H-BE SHALL comply with the SAML
> > 1.1 mapping of an eduGAIN AuthenticationResponse as described in the
> > corresponding section of this document.
> > · If an error occurs, the H-BE MUST return a SAML <Response> in
> > accordance with the SAML Browser/POST profile and coded according to
> > the rules described for the SAML mapping of eduGAIN
> > AuthenticationResponse with error results.
>
> So an ordinary Shib IdP should be able to connect to eduGAIN, as long as
> it uses a certificate issued according to eduGAIN rules. We have
> arlready demonstrated interoperability in the other direction: the
> CO-Manage demo site at http://comanage.internet2.edu/ accepts identity
> assertions coming from eduGAIN IdPs.
>
>
> Be goode,
>
>
> --
> "Esta vez no fallaremos, Doctor Infierno"
>
> Dr Diego R. Lopez
>
> Red.es - RedIRIS
> The Spanish NREN
>
> e-mail:
>
> jid:
>
> Tel: +34 955 056 621
> Mobile: +34 669 898 094
> -----------------------------------------
>
>
>



Archive powered by MHonArc 2.6.16.

Top of Page