Share-n-dipity

SharePoint serendipity is the effect by which one accidentally discovers something fortunate, especially while looking for something else entirely. In this case, it is the occassional musings, observations, and Ouija board readings about the phabulously

SharePoint Claims Auth Without SSL

SharePoint Claims Auth Without SSL

  • Comments 6
  • Likes

Someone asked me the other day whether we could use claims auth in SharePoint 2010 with ADFS v2 as the identity provider STS (STS-IP), but NOT use SSL on the SharePoint site.  In working through it, I found that there are some inherent limitations in making this happen, but not on the SharePoint side.  In ADFS when you define the relying party (SharePoint 2010 in this case), you have to define a WS-Fed endpoint.  When you do that, ADFS requires that the endpoint be SSL secured.  The endpoint when SharePoint 2010 is the relying part is protocol://siteUrl/_trust/.  In this case, since ADFS requires SSL for the WS-Fed endpoint, the protocol portion of the Url must be SSL.

So the short answer is, to use claims auth in SharePoint with ADFS, you must use SSL.  Other STS-IP implementations may not have this requirement, but ADFS v2 does.

Comments
Your comment has been posted.   Close
Thank you, your comment requires moderation so it may take a while to appear.   Close
Leave a Comment