Federation in ASP.net

From: Badrinath Mohan (bmohan@uncc.edu)
Date: 04/23/03


From: "Badrinath Mohan" <bmohan@uncc.edu>
Date: Wed, 23 Apr 2003 14:37:53 -0400


Hello folks

I am a new bie here and just joined today..

Has anyone done a bit of Federation concept.

I am trying to do that in windows 2003 and IIS 6.0 and i am facing some
problems.

I have made a passport authentication in my web site
(http://mypc.myschool.edu/testsite) and my IIS has the passport
authentication enabled. I also have a main site(http://mypc.myschool.edu)
where in i have the integrated windows authentication. I first go to
http://mypc.myschool.edu/testsite and then log in after submitting my
passport credentials. I then federate my passport account with the local
active directory account. After that when i go to http://mypc.myschool.edu i
am asked the windows dialog box for the credentials. How to bypass this..I
heard that once the account is federated i shall be able to do a single sign
on..Has anyone any idea about that..

Someone said me that i got to use LsaLogonUser for that to obtain a ticket
for my client automatically.
Has anyone implemented in any of ur cases.

why is the single sign on not working as i have logged in already using my
passport and have mapped successfully.

Am i goin in the right path??

Could anyone help me out please..
Would like to know ur answers
Expecting replies
Badrinath



Relevant Pages

  • Re: ADFS and Web SSO Scenario
    ... You can definitely just use the proxy's authentication UI to provide a forms ... you need to use a mapping scheme to map the external users to some ... group claims map to groups in the resource federation AD and have a token ... UPN that matches the UPN of a user on the resource federation AD. ...
    (microsoft.public.windows.server.active_directory)
  • Re: ADFS and Web SSO Scenario
    ... you need to use a mapping scheme to map the external users to some ... group claims map to groups in the resource federation AD and have a token ... UPN that matches the UPN of a user on the resource federation AD. ... I didn't realize there was an authentication ...
    (microsoft.public.windows.server.active_directory)
  • [NT] Microsoft Passport to Trouble
    ... Microsoft Passport to Trouble ... Passport accounts currently are actually Hotmail accounts). ... It does not allow for sufficient control over the use of authentication ...
    (Securiteam)
  • Re: ADFS and Web SSO Scenario
    ... it sounds like we need to create our own authentication scheme for this - ... claims apps using just the federation server and IWA. ... scenario (which can easily be extended to Federated Web SSO with Forest ...
    (microsoft.public.windows.server.active_directory)
  • [NEWS] Microsoft Passport Account Hijacking (Hacking Hotmail and more)
    ... Microsoft Passport Account Hijacking ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... measures and extended authentication methods have to be implemented into ... Many Web Mail Applications, such as Hotmail, ...
    (Securiteam)