To enable Shibboleth authentication within the Wiki goto the Admin page and in dropdown box select Shibboleth
When Selected Goto the bottom to the Shibboleth Seettings.
Below is a table of the options and what they do.
Option |
Description |
Default |
Create user if not registered in Tiki |
If a user was externally authenticated, but not found in the Tiki user database, Tiki will create an entry in its user database. |
Disabled |
Use Tiki authentication for Admin log-in |
The user “admin” will be authenticated by only using Tiki’s user database. This option has no effect on users other than “admin”. |
Disabled |
Valid affiliations |
A list of affiliations which will allow users to log in to this wiki Separate multiple affiliations with commas |
None |
Create with default group |
|
Disabled |
Default group |
The name of the default group |
Shibboleth |
Option |
Description |
Default |
Create user if not registered in Tiki |
If a user was externally authenticated, but not found in the Tiki user database, Tiki will create an entry in its user database. |
Disabled |
Use Tiki authentication for Admin log-in |
The user “admin” will be authenticated by only using Tiki’s user database. This option has no effect on users other than “admin”. |
Disabled |
Valid affiliations |
A list of affiliations which will allow users to log in to this wiki Separate multiple affiliations with commas |
None |
Create with default group |
|
Disabled |
Default group |
The name of the default group |
Shibboleth |
Option |
Description |
Default |
Create user if not registered in Tiki |
If a user was externally authenticated, but not found in the Tiki user database, Tiki will create an entry in its user database. |
Disabled |
Use Tiki authentication for Admin log-in |
The user “admin” will be authenticated by only using Tiki’s user database. This option has no effect on users other than “admin”. |
Disabled |
Valid affiliations |
A list of affiliations which will allow users to log in to this wiki Separate multiple affiliations with commas |
None |
Create with default group |
|
Disabled |
Default group |
The name of the default group |
Shibboleth |
Option |
Description |
Default |
Create user if not registered in Tiki |
If a user was externally authenticated, but not found in the Tiki user database, Tiki will create an entry in its user database. |
Disabled |
Use Tiki authentication for Admin log-in |
The user “admin” will be authenticated by only using Tiki’s user database. This option has no effect on users other than “admin”. |
Disabled |
Valid affiliations |
A list of affiliations which will allow users to log in to this wiki Separate multiple affiliations with commas |
None |
Create with default group |
|
Disabled |
Default group |
The name of the default group |
Shibboleth |
Option |
Description |
Default |
Create user if not registered in Tiki |
If a user was externally authenticated, but not found in the Tiki user database, Tiki will create an entry in its user database. |
Disabled |
Use Tiki authentication for Admin log-in |
The user “admin” will be authenticated by only using Tiki’s user database. This option has no effect on users other than “admin”. |
Disabled |
Valid affiliations |
A list of affiliations which will allow users to log in to this wiki Separate multiple affiliations with commas |
None |
Create with default group |
|
Disabled |
Default group |
The name of the default group |
Shibboleth |
Option |
Description |
Default |
Create user if not registered in Tiki |
If a user was externally authenticated, but not found in the Tiki user database, Tiki will create an entry in its user database. |
Disabled |
Use Tiki authentication for Admin log-in |
The user “admin” will be authenticated by only using Tiki’s user database. This option has no effect on users other than “admin”. |
Disabled |
Valid affiliations |
A list of affiliations which will allow users to log in to this wiki Separate multiple affiliations with commas |
None |
Create with default group |
|
Disabled |
Default group |
The name of the default group |
Shibboleth |
Option |
Description |
Default |
Create user if not registered in Tiki |
If a user was externally authenticated, but not found in the Tiki user database, Tiki will create an entry in its user database. |
Disabled |
Use Tiki authentication for Admin log-in |
The user “admin” will be authenticated by only using Tiki’s user database. This option has no effect on users other than “admin”. |
Disabled |
Valid affiliations |
A list of affiliations which will allow users to log in to this wiki Separate multiple affiliations with commas |
None |
Create with default group |
|
Disabled |
Default group |
The name of the default group |
Shibboleth |
Option |
Description |
Default |
Create user if not registered in Tiki |
If a user was externally authenticated, but not found in the Tiki user database, Tiki will create an entry in its user database. |
Disabled |
Use Tiki authentication for Admin log-in |
The user “admin” will be authenticated by only using Tiki’s user database. This option has no effect on users other than “admin”. |
Disabled |
Valid affiliations |
A list of affiliations which will allow users to log in to this wiki Separate multiple affiliations with commas |
None |
Create with default group |
|
Disabled |
Default group |
The name of the default group |
Shibboleth |
Option |
Description |
Default |
Create user if not registered in Tiki |
If a user was externally authenticated, but not found in the Tiki user database, Tiki will create an entry in its user database. |
Disabled |
Use Tiki authentication for Admin login |
The user “admin” will be authenticated by only using Tiki’s user database. This option has no effect on users other than “admin”. |
Disabled |
Valid affiliations |
A list of affiliations which will allow users to log into this Wiki. Separate multiple affiliations with commas |
None |
Create with default group |
|
Disabled |
Default group |
The name of the default group. |
Shibboleth |
Option |
Description |
Default |
Create user if not already a registered user |
If a user was externally authenticated, but not found in the Tiki user database, Tiki will create an entry in its user database. |
Disabled |
Use Tiki authentication for Admin login |
The user “admin” will be authenticated by only using Tiki’s user database. This option has no effect on users other than “admin”. |
Disabled |
Valid affiliations |
A list of affiliations which will allow users to log into this Wiki. Separate multiple affiliations with commas |
None |
Create with default group |
|
Disabled |
Default group |
The name of the default group. |
Shibboleth |
Option |
Description |
Default |
Create user if not already a registered user |
If a user was externally authenticated, but not found in the Tiki user database, Tiki will create an entry in its user database. |
Disabled |
Use Tiki authentication for Admin login |
The user “admin” will be authenticated by only using Tiki’s user database. This option has no effect on users other than “admin”. |
Disabled |
Valid affiliations |
A list of affiliations which will allow users to log into this Wiki. Separate multiple affiliations with commas |
None |
Create with default group |
|
Disabled |
Default group |
The name of the default group. |
Shibboleth |
Option |
Description |
Default |
Create user if not in Tiki |
If a user was externally authenticated, but not found in the Tiki user database, Tiki will create an entry in its user database. |
Disabled |
Use Tiki authentication for Admin login |
The user “admin” will be authenticated by only using Tiki’s user database. This option has no effect on users other than “admin”. |
Disabled |
Valid affiliations |
A list of affiliations which will allow users to log into this Wiki. Separate multiple affiliations with commas |
None |
Create with default group |
|
Disabled |
Default group |
The name of the default group. |
Shibboleth |
Option |
Description |
Default |
Create user if not in Tiki |
If a user was externally authenticated, but not found in the Tiki user database, Tiki will create an entry in its user database. |
Disabled |
Use Tiki authentication for Admin login |
The user “admin” will be authenticated by only using Tiki’s user database. This option has no effect on users other than “admin”. |
Disabled |
Valid affiliations |
A list of affiliations which will allow users to log into this Wiki. Separate multiple affiliations with commas |
None |
Create with default group |
|
Disabled |
Default group |
The name of the default group. |
Shibboleth |
Option |
Description |
Default |
Create user if not in Tiki |
If a user was externally authenticated, but not found in the Tiki user database, Tiki will create an entry in its user database. |
Disabled |
Use Tiki authentication for Admin login |
The user “admin” will be authenticated by only using Tiki’s user database. This option has no effect on users other than “admin”. |
Disabled |
Valid affiliations |
A list of affiliations which will allow users to log into this Wiki. Separate multiple affiliations with commas |
None |
Create with default group |
|
Disabled |
Default group |
The name of the default group. |
Shibboleth |
When the above is completed the wiki is ready to use shibboleth as an authentication source. You will now need to ensure that shibboleth is setup correctly.
Below are the files that were modified to enable Shibboleth Authentication;
- lib/userslib.php
- templates/modules/mod-login_box.tpl
- templates/tiki-admin-include-login.tpl
- tiki-admin_include_login.php
- tiki-setup_base.php
Below is a table of these files and a description of the changes;
File name | Description
| userslib.php | This is used to validate a shibboleth user, changes have been made to the validate_user function.
| tiki-admin-include-login.tpl | This file needs to be changed to display “Login through Shibboleth�? login box when not loged in.
| tiki-admin-include-login.tpl | This file needs to be changed to display the Shibboleth options in the Login Admin page
| tiki-admin_include_login.php | This file changes will process the new values in the Login Admin page above.
| tiki-setup_base.php | This page will need to be changed to ensure the shibboleth user is validated. |
|