supporting IdP-initiated SSO only

Tom Scavo trscavo at gmail.com
Sat Mar 16 14:31:14 EDT 2013


On Sat, Mar 16, 2013 at 2:15 PM, Peter Williams <pwilliams at rapattoni.com> wrote:
>
>  I'd say 80% of all saml2p-ish websso in US realty is idp-initiated. The only deployments where it's sp-initated always (almost) is when interworking with a commercialized Shib install. I'd say 99% of the transactions are idp-initiated.

Right, although the numbers certainly vary from federation to
federation, IdP-initiated SSO is very common. But I suspect you're
looking at this from an SP-centric PoV. Here I'm looking at this from
an IdP-centric PoV, such that IdPs can ease themselves into
federations. I get lots of requests from new organizations to
introduce "test IdPs" into production metadata but I push back hard on
such requests. Restricting your IdP to IdP-initiated SSO seems to be a
nice middle ground, I think.

Tom


More information about the dev mailing list