The Problem:

I want to implement a set of Webservices, protected with SAML. I need to authenticate the users, and also need to authorize based on the user role. I found some questions similar to this one, but none with satisfactory answers.

The scenario:

  • Java Webapp accessed only using Webservices;
  • SOAP - metro;
  • Clients use some Desktop application that they will develop.

Key features that I need:

  • Free software;
  • SAML 2.0;
  • LDAP(or similar solution) to manage users information;
  • Message level security (SOAP).

The question:

I study some SAML (SSO) solutions (e.g. Shibboleth, opemAM, JOSSO...);

  • Can I use any of those, without compromise any of the key features?
  • Or do I need to implement my own way to handle the SAML tokens?
  • How to do it?

Thank you!



Here are some results that I found, and/or some tips from the answers:

Edit
Report