Announcement Announcement Module
No announcement yet.
Offer of help with SAML module Page Title Module
Move Remove Collapse
Conversation Detail Module
  • Filter
  • Time
  • Show
Clear All
new posts

  • Offer of help with SAML module

    Hello, let me introduce myself. I work as one of the technical leads for the Shibboleth/OpenSAML projects. Over the last few days we have had a passionate individual post to our list regarding SAML support in Spring Security and Shibboleth interoperability. Within the Shibboleth project the SP implementation we have available plugs in to the web server (Apache/IIS/Netscape). We do not have a Java-native SP nor the resources, currently, to develop one. I know that Spring Security does have a SAML extension written by Vladimir and that a growing number of applications are using Spring Security.

    So, I wanted to at least extend a hand on behalf of myself and Scott Cantor, the other technical lead and one of the main editors of the SAML spec. As I mentioned above we're limited on development resources at the moment but if we can be of help I wanted to offer that. At the very least, testing and clarifying interoperability seems like a good thing (and I think was what the poster on our users list was getting at). In addition, I can review code (I'm pretty familiar with Spring core at least) and both Scott and I are willing to answer technical questions about the protocol, why we did certain things in our SP implementations, etc. I think having a high-quality Spring Security SAML module is a win for everyone so if we can be of help with that, just let us know.

    You can find us on the Shibboleth lists, the OASIS saml-dev list, or I'm also on the forums here, though Scott is not currently.

    -- Chad La Joie

  • #2
    Hi Chad,

    Thanks very much for the offer. I've always had a lot of respect for the Shibboleth project.
    Having quality integration between Spring Security and Shibboleth is something we'd definitely like to see and your offer of assistance from the Shibboleth/SAML side is most welcome. The last time I set up a Shibboleth instalation was pre-2.0, so I suspect things have changed a bit since then .

    I'll check out the post you mention and get back to you.

    Thanks again,



    • #3
      Hey Luke,

      The thread in question is here:

      It's a hijacked thread but the stuff about Spring starts with the Jan 9th post by rcrathore. I said this in the post, but let me re-iterate it here. I have *no* idea whether the current Spring Security SAML module is a good SP implementation or not. The concern I expressed to the poster comes solely from seeing a whole lot more bad SP implementations than good ones.

      As to the pre-2.0 software. Yeah, it's changed quite a bit since then. If you need help setting up an IdP for testing purposes let me know or if you'd prefer that we just try a couple quick tests with one of our existing IdPs against some test app that you have, as a start, that's certainly doable as well.


      • #4
        I consider myself to be well versed with Spring and Spring Security and would be happy to contribute.


        • #5
          I'd be happy to contribute as well. I'm no Spring-Security expert, but I've worked with OpenSAML before to create an InfoCard relying party (JInfoCard) and I've got some background in identity.



          • #6
            I'd love to assist with this wherever I can. I'm looking into integrating Shibboleth2 into a Spring Security-enabled web site, and CXF/Spring Security enabled web service project.

            I'm starting with integrating with Vladimir's code from the Spring git repo now.


            • #7

              How far did you get with integrating SAML Spring security extension with Shibboleth. I have setup shibboleth and currently integrating the security plugin. Would like to know if you hit any blockers or could provide some sample code/config.



              • #8
                getting there

                Congratulations to Vladimir and spring security team on SPRING SECURITY SAML 1.0.0.RC2 Release today.


                • #9
                  Thank you!


                  • #10
                    Hi I read the comments about helping out with the Shibboleth IDP and Springs Securtiy SAML Extention, I'm new to SAML and SSO but would like to get the Spring and Shibboleth running locally with the IDP using my own user repository application. Would you have any source I could look at to help me with my integration. Or any documentation or anything =)

                    Syed Shah


                    • #11
                      Hi Syed,

                      You might want to check the Spring SAML manual, you can find a quick start guide in chapter 3. The process of setting up a federation with Shibboleth is very similar to what's described there.