Shibboleth 可以与 Windows Azure 访问控制服务集成吗?
我们的两个高等教育客户使用 Shibboleth 进行 SSO。我对 Shib 的经验为零,并且没有可供测试的实例。
最终,我们希望将 Shib SSO 与 Windows Azure (MVC) Web 角色中的这些客户端集成。所以我的问题是:
- 这可能吗?
- 如果是这样,怎么办? Shib 上是否需要进行任何设置?这些设置是什么?
我去年在 MIX 11 上与 Vittorio Bertocci 讨论过这个问题。他告诉我有一个名为“WS-Federation”的复选框可以在 Shib 中启用,这将启用兼容性。我从客户那里了解到 服务提供商支持 WS-Fed,但不支持身份提供者。
我非常乐意在回复评论时用更多细节来补充这个问题。
Two of our higher-ed clients use Shibboleth for SSO. I have zero experience with Shib, and do not have an instance to test with.
Ultimately we would like to integrate a Shib SSO with these clients in our Windows Azure (MVC) web role. So my questions are:
- Is this possible?
- If so, how? Do any settings need to be make on Shib, and what are they?
I spoke with Vittorio Bertocci last year at MIX 11 about this. He told me there is a checkbox called "WS-Federation" that can be enabled in Shib, which would enable compatibility. I've learned from out clients that WS-Fed is supported on the Service Provider but not the Identity Provider.
I will be more than happy to supplement this question with more details in response to comments.
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(2)
在 Azure 端,您可以使用 WIF,它具有 扩展实施 SAML 2.0 协议(显然仍在 CTP 中)。
在这种情况下,您不会在两者之间使用 ACS。
警告:将 WIF 与ASP.NET MVC
:-)
本杰明
On Azure side, you would use WIF which has extensions to implement SAML 2.0 protocol (apparently still in CTP).
You would not use ACS in between in this case.
Warning: there are some gotchas while using WIF with ASP.NET MVC
:-)
Benjamin
如果 Azure 支持 SAML 2.0,那么它将或多或少地与 Shibboleth 进行互操作。如果它只支持 WS-Federation,那么它就不能满足您的目的。
If Azure supports SAML 2.0, then it will, more or less, interoperate with Shibboleth. If it only supports WS-Federation, then it won't for your purposes.