Confirmation required on a Mobile SSO design

Ashok Vijayakumar ashok.vijayk at gmail.com
Fri Dec 29 12:03:34 EST 2017


Hi Team,

On my project we are  making POC for Mobile Single Sign on, the technology
stack as below,

Identity Provider - Shibboleth {Authentication of user with JAAS Module }

Service Provider - Amazon Web service will be hosting our REST Services.

We decided to  authenticate the users of Mobile Application using
Shibboleth ECP end point.

We will  configure the IdP Session time out to the 6 months.

After the user being authenticated with Shibboleth ECP end point  for the
first time with the user name and password , the subsequent authentication
will be via shibboleth cookie received during first authentication.

We are planning to make this subsequent authentication requests with the
Shibboleth Cookie until the IdP Session expiry time.

It would be of great  help if  somebody could advice whether this approach
holds good and if not holding good detailed explanation on disadvantages of
the approach which will help us to move over to different approach for
designing Mobile SSO.

Thanks,
Ashok Vijayakumar.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/dev/attachments/20171229/6c1f6676/attachment.html>


More information about the dev mailing list