Important Notice: Our web hosting provider recently started charging us for additional visits, which was unexpected. In response, we're seeking donations. Depending on the situation, we may explore different monetization options for our Community and Expert Contributors. It's crucial to provide more returns for their expertise and offer more Expert Validated Answers or AI Validated Answers. Learn more about our hosting issue here.

We have a traditional grid deployment where each user has been issued a long-lived X.509 credential. Do each of the identity providers in our grid federation need to install GridShib for Shibboleth?

0
Posted

We have a traditional grid deployment where each user has been issued a long-lived X.509 credential. Do each of the identity providers in our grid federation need to install GridShib for Shibboleth?

0

Yes, in this case GridShib for Shibboleth is used to manage name mappings at the identity provider. Each user’s distinguished name (DN) is stored in a file or table so that the attribute authority can map the DN to a local principal name. To avoid having to install GridShib for Shibboleth at each IdP, an IdP Proxy may be used. IdP Proxy implementations include myVocs (a service) and myVocs box (an appliance).

Related Questions

Thanksgiving questions

*Sadly, we had to bring back ads too. Hopefully more targeted.