Re: Reverse Proxy Inetgration

Swergar Tsang <[email protected]> Fri, 04 Feb 2005 11:10:24 +0800
Newsgroups gmane.comp.sourceid.sso.user
Message-ID <[email protected]>
--===============1519336997==
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
  <meta content=3D"text/html;charset=3DUTF-8" http-equiv=3D"Content-Type"=
>
  <title></title>
</head>
<body bgcolor=3D"#ffffff" text=3D"#000000">
<font face=3D"Courier New, Courier, monospace">Dear </font><font
 face=3D"Courier New, Courier, monospace">Bryan, <br>
<br>
Thank you for your reply, I would like to </font><font
 face=3D"Courier New, Courier, monospace">describe the details here.<br>
<br>
<br>
</font><font face=3D"Courier New, Courier, monospace">There are more than
one SP&amp;IDP in my network, <br>
<br>
In which, users from different departments are authenticated by their
IDP <br>
and grant access to different SP resources by means of attrib like<br>
ranks, title or scores.<br>
<br>
Currently, some of our departments are using Novell ichains+edirectory
or <br>
SunOne Identity Server to provide such services. <br>
<br>
However, the above service is limited to a small group of people due to
security and <br>
license issue. I am exploring other resources that may fit into our
environment to <br>
provide same service to students, business parters or venders.<br>
<br>
<br>
Questions:<br>
<br>
1. Can I use SourceID in this environment?<br>
2. If yes, how can I get it work?<br>
3. If not 100% work, what are missing?<br>
4. For standard alone setup, can it use linux PAM for authentication?<br>
<br>
<br>
Simple work flow and network diagram are provided for your reference.<br>
<br>
<br>
</font><font face=3D"Courier New, Courier, monospace">Workflow:<br>
<br>
[user]---&gt;[sp]---(redirect)---&gt;[idp] (LDAP Authentication, PAM)<br>
<br>
[idp]----(ok, attribs are passed back to sp using SAML)----&gt;[sp]<br>
<br>
user---&gt;[sp] (reverse proxy) ---&gt; [backend servers]<br>
<br>
<br>
Network Diagram:<br>
<br>
<br>
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=
=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 [USERS]<br>
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=
=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 |<br>
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=
=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 (HTTPS)<br>
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=
=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 |=C2=A0=C2=
=A0=C2=A0=C2=A0=C2=A0=C2=A0 <br>
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 +-----=
------+-----------+<br>
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 |=C2=A0=
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=
=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 |<br>
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 +---+---+=C2=A0=C2=A0=C2=A0=C2=
=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 +---+---+=
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 +-----=
------+<br>
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 |=C2=A0=C2=A0 sp=C2=A0 |----(S=
AML)-----|=C2=A0 idp=C2=A0 |--(LDAPS)---|LDAP Server|<br>
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 +---+---+=C2=A0=C2=A0=C2=A0=C2=
=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 +-------+=
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 +-----=
------+<br>
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 |=C2=A0=
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 <br>
=C2=A0=C2=A0=C2=A0=C2=A0 (reverse proxy)<br>
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 |<br>
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 +-----=
----+---------+<br>
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 |=C2=A0=
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 |=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=
=C2=A0=C2=A0=C2=A0 |=C2=A0 <br>
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 +---+---+ +---+---+ +---+---+<=
br>
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 |Server | |Server | |Server |<=
br>
=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 +-------+ +-------+ +-------+<=
br>
<br>
<br>
Thank you for your great help.<br>
<br>
<br>
Best Regards,<br>
Swergar Tsang<br>
<br>
<br>
Bryan Field-Elliot wrote:</font>
<blockquote cite=3D"[email protected]"
 type=3D"cite">
  <meta http-equiv=3D"Content-Type" content=3D"text/html; ">
  <meta name=3D"GENERATOR" content=3D"GtkHTML/3.3.2">
  <font face=3D"Courier New, Courier, monospace">Swergar,<br>
  <br>
I'm not aware of any special requirements with respect to using
SourceID inside of a reverse proxy configuration. The Liberty SSO
protocol uses browser redirects, and in some cases server-to-server
SOAP calls, to do its work. As long as the DNS addresses of the servers
resolve validly to the end-user who is outside the reverse proxy, and,
optionally, as long as SourceID can issue a server-to-server SOAP call
when one (or both) installations is behind the proxy, then I don't see
you'd have any problems.<br>
  <br>
If you wish to describe the configuration in more detail for
discussion, feel free!<br>
  <br>
Thank you,<br>
  <br>
Bryan<br>
  <br>
  <br>
On Wed, 2005-02-02 at 09:52 +0800, Swergar wrote:
  </font>
  <blockquote type=3D"CITE">
    <pre><font color=3D"#000000" face=3D"Courier New, Courier, monospace"=
>Hello,</font><font
 face=3D"Courier New, Courier, monospace">

</font><font color=3D"#000000" face=3D"Courier New, Courier, monospace">I=
 would like to use reverse proxy concept to make non Liberty Alliance </f=
ont><font
 face=3D"Courier New, Courier, monospace">
</font><font color=3D"#000000" face=3D"Courier New, Courier, monospace">w=
eb applications to use SSO.</font><font
 face=3D"Courier New, Courier, monospace">

</font><font color=3D"#000000" face=3D"Courier New, Courier, monospace">H=
ow can I integrate SourceID with reverse proxy (apache, squid, tomcat </f=
ont><font
 face=3D"Courier New, Courier, monospace">
</font><font color=3D"#000000" face=3D"Courier New, Courier, monospace">.=
.. etc) ?</font><font
 face=3D"Courier New, Courier, monospace">


</font><font color=3D"#000000" face=3D"Courier New, Courier, monospace">T=
hank you.</font><font
 face=3D"Courier New, Courier, monospace">


</font><font color=3D"#000000" face=3D"Courier New, Courier, monospace">B=
est Regards,</font><font
 face=3D"Courier New, Courier, monospace">

</font><font color=3D"#000000" face=3D"Courier New, Courier, monospace">S=
wergar Tsang</font><font
 face=3D"Courier New, Courier, monospace">
</font><font color=3D"#000000" face=3D"Courier New, Courier, monospace">_=
______________________________________________</font><font
 face=3D"Courier New, Courier, monospace">
</font><font color=3D"#000000" face=3D"Courier New, Courier, monospace">s=
so-users mailing list</font><font
 face=3D"Courier New, Courier, monospace">
</font><font color=3D"#000000" face=3D"Courier New, Courier, monospace"><=
a
 href=3D"mailto:[email protected]">[email protected]</a></font>=
<font
 face=3D"Courier New, Courier, monospace">
</font><font color=3D"#000000" face=3D"Courier New, Courier, monospace"><=
a
 href=3D"http://lists.sourceid.org/mailman/listinfo/sso-users">http://lis=
ts.sourceid.org/mailman/listinfo/sso-users</a></font>
    </pre>
  </blockquote>
  <pre wrap=3D""><font face=3D"Courier New, Courier, monospace">
</font><hr size=3D"4" width=3D"90%"><font
 face=3D"Courier New, Courier, monospace">
_______________________________________________
sso-users mailing list
<a class=3D"moz-txt-link-abbreviated" href=3D"mailto:[email protected]=
rg">[email protected]</a>
<a class=3D"moz-txt-link-freetext" href=3D"http://lists.sourceid.org/mail=
man/listinfo/sso-users">http://lists.sourceid.org/mailman/listinfo/sso-us=
ers</a>
</font></pre>
</blockquote>
</body>
</html>

--===============1519336997==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
sso-users mailing list
[email protected]
http://lists.sourceid.org/mailman/listinfo/sso-users

--===============1519336997==--