The SecureW2 JoinNow platform integrates with Shibboleth to transform institutional SSO credentials into phishing-resistant network certificates. Users authenticate once via their existing directory to receive a phishing-resistant identity, and the platform automates the entire lifecycle, eliminating manual configuration and help desk tickets.
Overview
The SecureW2 JoinNow platform transforms your Shibboleth IdP into a secure foundation for passwordless network authentication. By acting as a SAML 2.0 service provider, the platform authenticates users via your institutional SSO and leverages returned identity attributes such as UID and affiliation to provision phishing-resistant X.509 certificates.
Cloud RADIUS then utilizes these encoded attributes to enforce role-based access policies and dynamic VLAN steering in real-time. This eliminates the need for on-premises PKI infrastructure while ensuring network access is automatically revoked the moment a Shibboleth-backed account is deprovisioned, maintaining a secure lifecycle without manual IT intervention.
Automatically assign users to secure VLANs or restricted network segments by mapping Shibboleth attributes to real-time Cloud RADIUS access policies. Faculty with “staff” affiliation are on the full corporate VLAN, students on “student” affiliation, and unrecognized identities are blocked at the RADIUS layer. Affiliation changes in the Shibboleth directory take effect at the next connection without certificate reissuance, as the policy is evaluated at every 802.1X authentication.
Link network access to the institutional directory to eliminate manual deprovisioning. When an account is suspended in Shibboleth, JoinNow detects the change and automatically revokes the associated certificate. The revocation is recorded in the SecureW2 Dynamic PKI’s CRL, and Cloud RADIUS checks CRL status at every EAP-TLS authentication event. At the next connection attempt, Cloud RADIUS returns a RADIUS Reject, closing network access without IT helpdesk intervention.
SecureW2 JoinNow, a SAML 2.0 service provider, connects to Shibboleth by exchanging SAML metadata and configuring Shibboleth’s attribute release policy to send user attributes to JoinNow during enrollment. To set up, register JoinNow SP metadata (Entity ID and assertion consumer service URL) in Shibboleth, upload Shibboleth IdP metadata (Entity ID, SSO endpoint URL, signing certificate) into JoinNow, and configure the attribute release policy to release uid, mail, eduPersonAffiliation, eduPersonPrincipalName, and ou to JoinNow SP.
In JoinNow, incoming SAML assertion attributes are mapped to identity fields in certificate templates and enrollment policy conditions, restricting issuance to specific users. JoinNow uses SP-initiated SSO: users visit the enrollment portal, JoinNow sends a SAML AuthnRequest to Shibboleth, and Shibboleth returns the assertion after authentication. IdP-initiated flows are not used for enrollment. JoinNow inherits Shibboleth IdP authentication requirements, including MFA via Duo, TOTP, or Shibboleth MFA plugins, eliminating the need for additional MFA configuration.
Deliver a seamless, self-service enrollment experience where students and faculty use their existing Shibboleth credentials to receive secure, phishing-resistant certificates for campus-wide Wi-Fi. When a user visits the JoinNow enrollment portal, they authenticate through their institution's Shibboleth SSO flow. JoinNow receives the SAML assertion, encodes the user's identity attributes, including eduPersonPrincipalName, into a certificate, and installs it on the device automatically. Cloud RADIUS is configured as the institution's home RADIUS server in the eduroam hierarchy, so the issued certificate works for campus Wi-Fi and at any eduroam-participating partner institution worldwide. No IT helpdesk involvement required. No shared passwords. No manual device configuration. Students and faculty connect securely from the moment enrollment completes.
Frequently Asked Questions
When the student's account is deprovisioned in the Shibboleth-backed LDAP directory, JoinNow CloudConnector can detect the change and automatically revoke the certificate. Cloud RADIUS will reject the certificate at the next authentication attempt. Administrators can also revoke certificates manually through the JoinNow admin console if immediate revocation is needed before the next scheduled LDAP sync.
Yes. JoinNow Cloud RADIUS supports the eduroam RADIUS federation. Certificates issued with the user's eduPersonPrincipalName in the SAN are recognized by eduroam-participating institutions. Institutions configure JoinNow as their home RADIUS server in the eduroam hierarchy. Users can authenticate at partner institutions without any changes to their device.
Certificates can be revoked immediately through the JoinNow admin console. Revocation takes effect at the next EAP-TLS authentication attempt Cloud RADIUS checks OCSP or CRL status on every connection. Users can re-enroll a replacement device through the self-service portal after an administrator clears the revoked enrollment record.
Connect with our integration specialists to implement this solution in your environment and transform your security posture.