Skip to Content.
Sympa Menu

technical-discuss - RE: [InC-Technical] RE: ADFS InCommon Federated Services Help

Subject: InCommon Technical Discussions

List archive

RE: [InC-Technical] RE: ADFS InCommon Federated Services Help


Chronological Thread 
  • From: "Matthew X. Economou" <>
  • To: "Eric C Kool-Brown" <>, <>, <>
  • Subject: RE: [InC-Technical] RE: ADFS InCommon Federated Services Help
  • Date: Thu, 8 Feb 2018 21:09:54 -0500
  • Ironport-phdr: 9a23:EmbMyBVDUVgJ52g5aOA45Ewt+6LV8LGtZVwlr6E/grcLSJyIuqrYbRSBt8tkgFKBZ4jH8fUM07OQ7/i5HzRYqb+681k6OKRWUBEEjchE1ycBO+WiTXPBEfjxciYhF95DXlI2t1uyMExSBdqsLwaK+i764jEdAAjwOhRoLerpBIHSk9631+ev8JHPfglEnjWwba9vIBmssQndqtQdjJd/JKo21hbHuGZDdf5MxWNvK1KTnhL86dm18ZV+7SleuO8v+tBZX6nicKs2UbJXDDI9M2Ao/8LrrgXMTRGO5nQHTGoblAdDDhXf4xH7WpfxtTb6tvZ41SKHM8D6Uaw4VDK/5KpwVhTmlDkIOCI48GHPi8x/kqRboA66pxdix4LYeZyZOOZicq/Ye94URW1BXtxeVyNfH4y3cpcPD+oAPelFsoLxo0UCoQe7CQSqGejhyCJHhmXu0KM83OsuDQ7I0hE5EdwAs3rUsNX7OrkJXOCp16bFzinPY+9K1Tr/7oXDbxAvoeuLXbJ1acfdx04hGBnZjlWMqYzqIT2U3fkMvGSB8uFuWv6gi2khqwF2pzivwdoshofUjY8SxVHL6yN5wIEtJd24T057Z8WpEJpKtyGGMYt2RcwiT3tvuCYgxb0LoJi2dzUJxpQ/3xPTdfOKf5KV7h79WuudOyp0iXx/dL++mhq/91WrxPfmWcmuyllKqzJIktnSuXAJ0Bze8s2HS/Rg8ku72DaPzRzT6udDIUA7j6bbLIQhwrEompoSt0TMADP2lV3ogKKZbEko5/ak5ur9brn7qJKQLY55hhzmPqQrgMO/AOA4MgYUX2ic/OSxzLLi8lP/QLVNlv02kq7ZsJbBKMQavK65HwlV0oEs6xqlCDemytsYkWEdLF1ZYBKHk5TpO1bWLfD5C/ewn1OskDJux/DBOL3tGJLNLmLMkLv4YbZy9VJTyAo1zdBe+51bELUBLOvuVU/wr9zXEgI5Mxevw+v8DNV915geWX6UAqOHKq/SsFmI5v4xLOmWYo8apir9J+Y/6/HwkHA5hAxVQa78l7YNaXvwNbxFJEKdJFD2hcgHWy9evQ05SMT3lxuPXSMFIz7mQ6835jc6A4uiSIvCXYuwm6ep3SGwGZhTYWYADUqDRzOgI4yAVucFbi6IL4lonjUDfb2mUYAo01ejuBKsmJR9Ke+BsAgRqY7j2cc916ubuBo18ztxCNnXmzWdQmdzhmMPQRc3xrx5pkM7zU2Mh/sry8dEHMBesqsaGjwxMoTRmqkqU90=

Eric C. Kool-Brown writes:

> I think I left off one bit of perhaps relevant info regarding the
> second use case of ADFS as the IdP. The ADFS metadata (as a service
> provider) would need to be added to the InCommon aggregate in order to
> be trusted by the other InCommon IdPs. I suppose that ADFS could also
> have IdP metadata added so it could be a full federation partner as
> well. Does anyone on the list know of a federation member that has done
> either of these things?

I've run AD FS both as an InCommon IdP and an InCommon SP, with both as full
federation partners. While we solved the metadata consumption, attribute
scope checking, and discovery UX issues, we encountered lots of little issues
that required disabling request/assertion encryption or switching between
SHA-1/SHA-256 on individual CP/RP trusts. Ultimately, we replaced the IdPs
with Shibboleth and moved the SPs behind SATOSA. This works a LOT better,
which is why I'm willing to use some of my Copious Free Time to help Mr. Adao
deploy Shibboleth.

Best wishes,
Matthew

--
"The lyf so short, the craft so longe to lerne."




Archive powered by MHonArc 2.6.19.

Top of Page