[phpldapadmin] Fwd: [ phpldapadmin-Feature Requests-2073323 ] Using Single Sign On authentication

"Clément OUDOT" <[email protected]>
Newsgroups gmane.comp.ldap.davedap
Message-ID <[email protected]>
Hello,

I'm new to this list, I join after a message from Deon George (I
forward our discussion). I would like to help you adding the support
of Authz-proxy LDAP control, in order to support external
authentication.

More info on this control : http://tools.ietf.org/html/rfc4370

Clément.

---------- Forwarded message ----------
From: SourceForge.net <[email protected]>
Date: 2008/11/28
Subject: [ phpldapadmin-Feature Requests-2073323 ] Using Single Sign
On authentication
To: [email protected]


Feature Requests item #2073323, was opened at 2008-08-25 20:14
Message generated for change (Comment added) made by wurley
You can respond by visiting:
https://sourceforge.net/tracker/?func=detail&atid=498549&aid=2073323&group_id=61828

Please note that this message will contain a full copy of the comment thread,
including the initial issue submission, for this request,
not just the latest update.
Category: None
Group: None
Status: Open
Priority: 5
Private: No
Submitted By: Clement OUDOT (clement_oudot)
Assigned to: Nobody/Anonymous (nobody)
Summary: Using Single Sign On authentication

Initial Comment:
Hello all,

I'm contributor of LemonLDAP::NG, a webSSO product able to manage
access rights to applications. I try to protect PLA with this SSO.

For now, I've set up auth_type to 'config', and protect access to PLA
by the webSSO, which works but the user connected to PLA is the one
set inside config.php, and not the user connected to the webSSO.

I would like to provide help to go further: I think we can imagine a
new auth_type ('sso' for example, or 'external' to be more generic)
with the following functionnality:
- When PLA see 'sso' auth_type, it checks inside HTTP HEADERS for user
login (attr or complete DN)
- PLA use the DN and Password used for 'config' auth_type but use also
"Proxy Authorization Control" so that the connection is done with the
DN provided by the WebSSO.

This could be great, so that PLA could be integrated with CAS,
LemonLDAP::NG and all Apache auth modules (Kerberos, SSL, etc.)

Does it interest you? Can you help me to write the patch?

Clement.


----------------------------------------------------------------------

Comment By: Deon George (wurley)
Date: 2008-11-29 02:16

Message:
Clement, this sounds interesting - tell me about this Proxy Authorization
Control... Might be good to join the devel mailling to discuss this. :)

----------------------------------------------------------------------

You can respond by visiting:
https://sourceforge.net/tracker/?func=detail&atid=498549&aid=2073323&group_id=61828

-------------------------------------------------------------------------
This SF.Net email is sponsored by the Moblin Your Move Developer's challenge
Build the coolest Linux based applications with Moblin SDK & win great prizes
Grand prize is a trip for two to an Open Source event anywhere in the world
http://moblin-contest.org/redirect.php?banner_id=100&url=/
______________________________________
phpLDAPadmin development mailing list.
To unsbuscribe: https://lists.sourceforge.net/lists/listinfo/phpldapadmin-devel
http://phpldapadmin.sourceforge.net/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.