Practical documents
SimpleSAMLphp for service providers and identity providers
SimpleSAMLphp software makes it possible to add single sign-on functions to an existing authentication infrastructure by means of the SAML 2.0 protocol. SimpleSAMLphp can act as an identity provider – so as to utilise existing authentication sources – and as a service provider.
Read the manual (pdf)
Ways of connecting up with a federation
Institutions can connect up with a federation in a number of different ways. This document will help you select the right one. It describes an easy, future-proof method for connecting up your institution with a federation on the basis of the institution’s IAM infrastructure (ELO, Active Directory, or an IAM package).
Read the guidelines (pdf, in Dutch)
Connecting up with SURFfederatie from a Microsoft environment
This document tells you how to connect up with SURFfederatie from an environment based on Microsoft products. This involves using a proxy, which can be set up in two different ways: as an AD FS or as an ISA proxy. In the latter case, home users or mobile users can also benefit from the advantages of single sign-on between the services inside and outside the institution.
Read the guidelines (pdf, in Dutch)
ADFS-IDP
Instructions for connecting as an identity provider with the aid of Microsoft Active Directory Services version 2.0 (ADFS 2.0), making it possible to access an account database that is based on Microsoft Active Directory (AD). The current version of the manual is version 2.0, which makes use of the SAML 2.0 protocol.
Read the manual (pdf, in Dutch)
Novell Access Manager
Novell provides instructions in a “white paper” for connecting to SURFfederatie with Novell Access Manager 3.0. The white paper describes how Novell Access Manager can be used by both identity providers and service providers. The current version is 2.0 (December 2008).
Read the white paper (pdf, in Dutch)
Google Apps recommendations
This document describes the relationship between Google Apps and SURFfederatie. We also make recommendations for setting up a Google Apps environment utilising federative authentication.
Read the recommendations (pdf, in Dutch)