20 likes | 157 Vues
This diagram provides a simplified overview of SAML communication between a student at Starbucks and a university's protected web services. It illustrates the interaction between the Shibboleth Identity Provider (IdP) at the student's school and the Shibboleth Service Provider (SP). Key components include the browser session used for attribute exchange and the role of the shibd daemon in managing state. Learn how authentication works and how access to protected services is controlled, emphasizing the integration of identity management systems like Active Directory.
E N D
Obligatory Geek Diagram – Simplified Student is at Starbucks IdP/SP communication via SAML attributes exchanged through the browser session Protected Web Service is at a university IdP is at his school Shibboleth Identity Provider (IdP) Shibboleth Service Provider (SP) (mod_shib gets attributes from shibd and protects web apps) Access to protected service (web app) is controlled by shib gatekeeper (shibd daemon maintains state) (IdP is a J2EE app) Active Directory Server