Re: Reverse Proxy Inetgration

Bryan Field-Elliot <[email protected]> Thu, 03 Feb 2005 06:11:36 -0700
Newsgroups gmane.comp.sourceid.sso.user
Message-ID <[email protected]>
--===============0360864063==
Content-Type: multipart/alternative; boundary="=-0XsgLR1Xtrp5Fo+D45mI"


--=-0XsgLR1Xtrp5Fo+D45mI
Content-Type: text/plain
Content-Transfer-Encoding: 7bit

Swergar,

I'm not aware of any special requirements with respect to using SourceID
inside of a reverse proxy configuration. The Liberty SSO protocol uses
browser redirects, and in some cases server-to-server SOAP calls, to do
its work. As long as the DNS addresses of the servers resolve validly to
the end-user who is outside the reverse proxy, and, optionally, as long
as SourceID can issue a server-to-server SOAP call when one (or both)
installations is behind the proxy, then I don't see you'd have any
problems.

If you wish to describe the configuration in more detail for discussion,
feel free!

Thank you,

Bryan


On Wed, 2005-02-02 at 09:52 +0800, Swergar wrote:

> Hello,
> 
> I would like to use reverse proxy concept to make non Liberty Alliance 
> web applications to use SSO.
> 
> How can I integrate SourceID with reverse proxy (apache, squid, tomcat 
> ... etc) ?
> 
> 
> Thank you.
> 
> 
> Best Regards,
> 
> Swergar Tsang
> _______________________________________________
> sso-users mailing list
> [email protected]
> http://lists.sourceid.org/mailman/listinfo/sso-users

--=-0XsgLR1Xtrp5Fo+D45mI
Content-Type: text/html; charset=utf-8
Content-Transfer-Encoding: 7bit

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 TRANSITIONAL//EN">
<HTML>
<HEAD>
  <META HTTP-EQUIV="Content-Type" CONTENT="text/html; CHARSET=UTF-8">
  <META NAME="GENERATOR" CONTENT="GtkHTML/3.3.2">
</HEAD>
<BODY>
Swergar,<BR>
<BR>
I'm not aware of any special requirements with respect to using SourceID inside of a reverse proxy configuration. The Liberty SSO protocol uses browser redirects, and in some cases server-to-server SOAP calls, to do its work. As long as the DNS addresses of the servers resolve validly to the end-user who is outside the reverse proxy, and, optionally, as long as SourceID can issue a server-to-server SOAP call when one (or both) installations is behind the proxy, then I don't see you'd have any problems.<BR>
<BR>
If you wish to describe the configuration in more detail for discussion, feel free!<BR>
<BR>
Thank you,<BR>
<BR>
Bryan<BR>
<BR>
<BR>
On Wed, 2005-02-02 at 09:52 +0800, Swergar wrote:
<BLOCKQUOTE TYPE=CITE>
<PRE>
<FONT COLOR="#000000">Hello,</FONT>

<FONT COLOR="#000000">I would like to use reverse proxy concept to make non Liberty Alliance </FONT>
<FONT COLOR="#000000">web applications to use SSO.</FONT>

<FONT COLOR="#000000">How can I integrate SourceID with reverse proxy (apache, squid, tomcat </FONT>
<FONT COLOR="#000000">... etc) ?</FONT>


<FONT COLOR="#000000">Thank you.</FONT>


<FONT COLOR="#000000">Best Regards,</FONT>

<FONT COLOR="#000000">Swergar Tsang</FONT>
<FONT COLOR="#000000">_______________________________________________</FONT>
<FONT COLOR="#000000">sso-users mailing list</FONT>
<FONT COLOR="#000000"><A HREF="mailto:[email protected]">[email protected]</A></FONT>
<FONT COLOR="#000000"><A HREF="http://lists.sourceid.org/mailman/listinfo/sso-users">http://lists.sourceid.org/mailman/listinfo/sso-users</A></FONT>
</PRE>
</BLOCKQUOTE>
</BODY>
</HTML>

--=-0XsgLR1Xtrp5Fo+D45mI--


--===============0360864063==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
sso-users mailing list
[email protected]
http://lists.sourceid.org/mailman/listinfo/sso-users

--===============0360864063==--