cosign

enterprise & friends

| | | |

the lists.u.washington login sequence is a simple wayf, if from
u.washington login here else login there. this type of
"enterprise&friends/others" wayf will be a typical user collection
senario.

thinking about the cosign implementation and comparing to pubcookie and
shib, you can think of them as an ever increasing scope of user bases.
pubcookie is single domain, cosign is two domains (enterprise and friends)
both "hosted" but the same site, and shib is a 2 or more solution though
the complexity of shib suggests you better have a lot to justify the work.

response from Cosign developers (johanna bromberg craig) -brief overview of components

|

Here's a brief overview of the components. The CGI & Daemon make up
"Weblogin" in the diagram. Filter is the cosign part that runs on
"Service" in the diagram.

cgi: The central cgi is responsible for logging users into and out of
the central cosign server. It is also responsible for registering each
service a user logs into - this action ties the user's central login
cookie to their session on individual application servers such as our
web mail client, web directory client, or CourseTools environment. The
prototype CGI was built to use Kerberos V/GSSAPI to authenticate the

Syndicate content