cancel
Showing results for 
Search instead for 
Did you mean: 

Hyland.Services and Single Sign-On - Supported? Scenario given

Jeffrey_Seaman
Star Contributor
Star Contributor

Is Hyland.Services compatible with Single Sign-On?  I am not able to find a single reference to Single Sign-on in the Hyland.Services portion of the SDK.  The only methods listed under the Connect request are OnBase authentication, Domain, NT, and Query Metering.

Whether or not it is directly supported, here is a description of the scenario we are facing.

  • OnBase is currently using LDAP authentication.
  • The customer wishes to start using Single Sign-on.
  • The customer is using Novell Access Manager which QA said we should be able to integrate with using SSO's SAML 2.0 integration.
  • The customer is building a custom application which they wish to integrate with OnBase.
  • The customer's vision is that the user signs into the custom application which authenticates against Novell Access Manager.  The user then would not need to sign into OnBase as they have validated against the customer application (the custom application would pass the proper SAML token to authenticate as the user that signed into the custom application).  The application would use the Pop integrations in some scenarios and Hyland.Services in others.
  • Because it is a web-based application, all Hyland.Services calls would be performed from the custom application's application server.
  • The OnBase web servers and Novell Access Manager/custom application are hosted on different domains.

If anyone has any opinions or insight as to the feasability of this scenario, it would be much appreciated.  We would like to know what we are getting into before delving too deep.

Thanks in advance.

2 REPLIES 2

Ian_Cordova
Champ on-the-rise
Champ on-the-rise

Hi Jeffery,

There several questions that I have that might be easier to discuss via conference call.  But from a very high-level, OnBase Single Sign-On should work.  The one item that I am not sure is the authentication portion of the solution.  For example, one of the bullet points states it is using a custom application that integrates with OnBase and is used for authentication.  So does the custom solution authenticate to Novell Access Manager through an API call or does an ISAPI type filter redirect the request to a Novell Access Manager page that the user then authenticates and is redirected back to the custom application? 

Ultimately as long as either the SAML 2.0 token can be HTTP POST to the OnBase Web Client (Novell Access Manager Authentication) or the username is somewhere in the HTTP request during the Hyland.Services connect request, this should be possible. 

Please let me know if you are interested in having a conference call to discuss.

Thanks,

Ian Cordova

Ian,

Sorry for the delay, but I am just seeing your reply now (I thought I'd get an email alert if a reply was made).  A conference call to discuss this in more detail would be great.  We've had a few more discussions with the customer and the developer of the custom application and I'm not 100% sure we're heading in the right direction.  I think most of my questions will gravitate more toward SSO as I'm trying to figure out exactly how it will play into the scenario the customer is describing.

If you could hit me up via email (I take it you have access to my contact info), I'd like to get a call scheduled so we can discuss these items.

Thanks,

Jeffrey Seaman