ADFS 2.0 SP Initiated

Cantor, Scott cantor.2 at osu.edu
Fri Jan 11 10:08:06 EST 2013


On 1/11/13 10:04 AM, "j.sperling at fh-bingen.de" <j.sperling at fh-bingen.de>
wrote:
>
>my colleague and i have a problem with the SP Initiated Login.
>We have a Shibboleth as Service Provider and a ADFS 2.0 as IDP.
>I configured the SSO Configuration in the shibboleth2.xml but we don´t
>know the discoveryURL from the ADFS.

Please take any follow up questions to the users list, this isn't a dev
question.

>Are we in the right corner of the problem?

Not really. A discoveryURL is for discovery, not SSO. ADFS does not
support any discovery protocols, or at least none standardized that the SP
supports. So one question to ask is whether you have one IdP or many.

>When i go to my secured place (http://mydomain.com/secure) and i don´t
>have a Token. The SP redirect me to the ADFS IdP or not? But how he
>redirect me? Over the discoveryURL? or somethine else?

Metadata. If you're using SAML, it's same as any other IdP. If WS-Fed, see
https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPADFS

-- Scott





More information about the dev mailing list