SingleSignOn with ADFS in my Classic ASP site?

Posted on 2013-01-02
Last Modified: 2013-02-08
I have a Classic ASP site, hosted on Windows 2003, IIS 6. My client would like to have SSO (SingleSignOn) using his ADFS, instead of my own self built user login system. Is there an easy way to do this, where someone have already built the wheel, so integration will be easy?

My system is SaaS, hosted externally from the client ADFS.

Can someone explain me ADFS structure and how to accomplish this?
Question by:jawsdk
  • 3
  • 2
LVL 77

Expert Comment

ID: 38738663
Disable anonymous logins, let the user be prompted or authentication, then your ASP have to look at the environment variables to identify the user that logged in and rely on your nternal mask for what rights the user has.

Author Comment

ID: 38750722
arnold: I guess this will only work when IIS is on same internal network as users. But as I told, this is externally hosted SaaS system, so we cant do this.
LVL 77

Expert Comment

ID: 38751009
One way is they need to periodically export their AD data and for you to import it. Or you can tie your app to proxy/remote connect to their AD.

What options do you have on your own systems?

Author Comment

ID: 38751030
They are using ADFS (not good old AD) and as far as I can read, this is especially good to do SSO with external providers, like me. But that is as far as I can come...
LVL 77

Accepted Solution

arnold earned 500 total points
ID: 38751084
Your code instead of accessing the local db, will need to connect to their adfs server.
Not sure whether you can use classic asp to remotely exchange SAML messages.
Discusses creating a SSL while maintaining the site as is.

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

In this article, we will see the basic design consideration while designing a Multi-tenant web application in a simple manner. Though, many frameworks are available in the market to develop a multi - tenant application, but do they provide data, cod…
This article shows how to deploy dynamic backgrounds to computers depending on the aspect ratio of display
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

815 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now