Shibboleth IDP 3 as CAS Server
Marvin Addison
marvin.addison at gmail.com
Fri Jun 12 11:33:15 EDT 2015
>
> I didn't realize the ticket validation depended on the IdP session
The main requirement for an IdPSession is for tracking an SPSession to
support SLO, which is an important use case in CAS. I suppose that could be
made optional, which I recall is what you did in the SAML SSO flows.
The other prominent case is that I couldn't figure any other way for
determining a principal name other than by digging it out of the IdP
session; see BuildAttributeContextAction for an example.
M <dev-unsubscribe at shibboleth.net>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/dev/attachments/20150612/9f3f8a1d/attachment.html>
More information about the dev
mailing list