Solved

Apache web application(s) as Service Provider - ADFS 2.0 as IDP

Posted on 2014-10-16
4
103 Views
Last Modified: 2016-06-19
Hi,

I have encountered an Enterprise environment with redundant ADFS 2.0 federation servers and Federation proxies. There is an two way trust to an supplier network (the trust will get decommissioned). In the supplier network there is an basic configuration of adfs 3.0 with the regarding WAP servers. Supplier network runs several type of applications. Oracle based apps, Linux based apps running running on Apache 2.x (LAMP) and Microsoft apps.

The question is now mainly focused on the LAMP applications

I have Googled a bit and found the following results:
Spring SAML could be used to make a LAMP application act as Service Provider (SAML 2.x). This is configured within the application.
Shibboleth is used to make Apache act as an service provider

What are the best practices to make Linux Apache applications Service Provider? Communicating with ADFS 2.0
Is there any by Microsoft recommended 3rd party software to use

Note: Security is a huge issue that need to be taken into consideration.

Thank you in advance for your time and effort.

Best regards,
Reza
0
Comment
Question by:RSayadi
  • 2
4 Comments
 
LVL 1

Author Comment

by:RSayadi
ID: 40398745
scanario-01.jpg
0
 
LVL 62

Expert Comment

by:gheist
ID: 40409381
In primitive means apache can support SSO via samba's winbindd.
0
 
LVL 1

Accepted Solution

by:
RSayadi earned 0 total points
ID: 40491524
Solution is to use a simpleSAMLphp or shibboleth kind of product for LAMP applications and add it to ADFS 3, where ADFS 3 can be a SP for ADFS 2 in this scenario. The Oracle OBIEE 9+ (weblogic has built in SAML authentication support and can act as an SP and/or IDP.

This question can be closed
0

Featured Post

Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Short answer to this question: there is no effective WiFi manager in iOS devices as seen in Windows WiFi or Macbook OSx WiFi management, but this article will try and provide some amicable solutions to better suite your needs.
This script can help you clean up your user profile database by comparing profiles to Active Directory users in a particular OU, and removing the profiles that don't match.
The viewer will learn how to successfully download and install the SARDU utility on Windows 8, without downloading adware.
The viewer will learn how to successfully download and install the SARDU utility on Windows 7, without downloading adware.

803 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question