We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 7406
    • 3 Posts
    Hello, I am under the impression that shibboleth-authentication can be done with modx, however I can not find instructions/module to do this?
    So do I need to write it myself and if so, where should I start?

    I only just dowloaded modx to try out, and it looks very good so far! I have to set up shibboleth authentication (quickly!) and as no CMS yet supports it, I figured I’d try this one out as it also looks quite clean and understandable from the coding point of view.

    Can anyone point me in the right direction?

      • 28042 ☆ A M B ☆
      • 24,524 Posts
      Never heard of it before.
      http://shibboleth.internet2.edu/
        Studying MODX in the desert - http://sottwell.com
        Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
        Join the Slack Community - http://modx.org
        • 7406
        • 3 Posts
        Well, yes, we have shibboleth-sp set up on our server, now we need to modify modx to use it.
        So I was hoping for some pointers on the authentication system that modx uses, and what to change so it can utilize the shibboleth server variables.

        Edit: Ok, I was able to modify and use the IMAP-login plugin so that it grabs my shibboleth-username and sets mgrValidated session variable to 1.
        Still, it presents me with the login form, so I need to get rid of the login form completely. What other session variables should I set, or what other actions do I have to take so my authentication will be "complete"?

        For those who don’t know, shibboleth outsources the login procedure to one’s own institution, so that individual apps can
        a) forget all about user passwords and their management and let shibboleth do it (single sign-on)
        b) allow people from different institutions to login to the one application, authenticating at their own institutions single sign-on app.
        c) grab attributes (email, full name, group memebership, home institution and so on) from header values of shibboleth authenticated users, so users don’t have to fill in the details themselves

        So the application itself does not have to manage passwords, and also users only have one password which is good for all apps that require logging in. Of course we stiill need authorization, but that can be taken care of by the app based on local settings OR, if applicable, shibboleth-attributes (group membership etc)


          • 22770
          • 285 Posts
          PatrickSamphire Reply #4, 19 years ago
          If you figure out a snippet or module to do this, please put it in the repository! My institution uses Shibboleth, but I don’t really know how it works, and anyway, I think it’s far beyond my abilities! It would be enormously useful, though.
            • 25663 MODX Staff
            • 12,272 Posts
            Ping jaredc on the forums here, as I believe Ohio State University College of Veterinary Medicine uses shiboleth for all authentication, and he’s in charge of the web development there.
              Ryan Thrash, MODX Co-Founder
              Follow me on Twitter at @rthrash or catch my occasional unofficial thoughts at thrash.me
              • 7406
              • 3 Posts
              Quote from: rthrash at Oct 05, 2007, 07:15 AM

              Ping jaredc on the forums here, as I believe Ohio State University College of Veterinary Medicine uses shiboleth for all authentication, and he’s in charge of the web development there.

              Thank you very much for this information!

              Shibboleth can be quite daunting at first, but for software developers (as opposed to sysadmins smiley) it is really quite simple. Once you are authenticated at the single sign-on service, you are redirected back to where you came from, at at that point the apache module mod_shib takes care of the attribute query: php can access the attributes that you get from the Identity provider as they are stored in the $_SERVER variable, with names such as $_SERVER[’SHIB_EP_PRICINPALNAME’] and so forth. mod_shib apache module takes care of the shibboleth session, checking for expiration and validity of session, freshness of attributes, authzn and so on. Old fashioned .htaccess is used to limit access to shibboleth-protected resources.

              The tricky bit is coverting old-fashioned apps to utilize the information available in the $_SERVER-variable as most apps have their own session management. This is the bit I’m having a bit of trouble with smiley
                • 13577
                • 302 Posts
                Indeed we use it.

                I’ve developed a MODx application in which the user is automatically set up as a MODx user. My thinking was that then I could use the MODx tools to limit navigation, access, etc. It’s turned out to be a big pain in the neck however, because our MODx user management is becoming cumbersome. Subsequent MODx applications have their own user privileges, security etc, built in at the application level instead. I still capture login credentials from Shibboleth to identify them, I just don’t convert them to MODx users. That seems to be working much better.

                I have not *mastered* Shib at all - but I’m willing to tell you what I [think I] know. If you want to PM me, that’d be fine. If we collectively come up with something the group can use, we can post back. But my suspicion is that this is a bit esoteric for most - and some of the details shouldn’t be splattered all over the net... let’s see, to attack Jared’s apps I just need to...
                  Standard Disclaimer
                  I could be totally wrong.