Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

SingleSignOn with ADFS in my Classic ASP site?

Posted on 2013-01-02
5
Medium Priority
?
1,974 Views
Last Modified: 2013-02-08
I have a Classic ASP site, hosted on Windows 2003, IIS 6. My client would like to have SSO (SingleSignOn) using his ADFS, instead of my own self built user login system. Is there an easy way to do this, where someone have already built the wheel, so integration will be easy?

My system is SaaS, hosted externally from the client ADFS.

Can someone explain me ADFS structure and how to accomplish this?
0
Comment
Question by:jawsdk
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
5 Comments
 
LVL 79

Expert Comment

by:arnold
ID: 38738663
Disable anonymous logins, let the user be prompted or authentication, then your ASP have to look at the environment variables to identify the user that logged in and rely on your nternal mask for what rights the user has.
http://stackoverflow.com/questions/13148226/access-iis-server-variables-in-nancy-module
http://forums.asp.net/t/1540119.aspx
0
 

Author Comment

by:jawsdk
ID: 38750722
arnold: I guess this will only work when IIS is on same internal network as users. But as I told, this is externally hosted SaaS system, so we cant do this.
0
 
LVL 79

Expert Comment

by:arnold
ID: 38751009
One way is they need to periodically export their AD data and for you to import it. Or you can tie your app to proxy/remote connect to their AD.

What options do you have on your own systems?
0
 

Author Comment

by:jawsdk
ID: 38751030
They are using ADFS (not good old AD) and as far as I can read, this is especially good to do SSO with external providers, like me. But that is as far as I can come...
0
 
LVL 79

Accepted Solution

by:
arnold earned 1500 total points
ID: 38751084
Your code instead of accessing the local db, will need to connect to their adfs server.
http://msdn.microsoft.com/en-us/magazine/cc163520.aspx
Not sure whether you can use classic asp to remotely exchange SAML messages.


http://stackoverflow.com/questions/5958575/saml-2-0-browser-post-profile-single-sign-on-to-classic-asp-web-site
Discusses creating a asp.net SSL while maintaining the site as is.
0

Featured Post

Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

After seeing many questions for JRNL_WRAP_ERROR for replication failure, I thought it would be useful to write this article.
Let's recap what we learned from yesterday's Skyport Systems webinar.
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…

715 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question