Confirmation required on a Mobile SSO design

Cantor, Scott cantor.2 at osu.edu
Fri Dec 29 18:04:03 EST 2017


On 12/29/17, 12:03 PM, "dev on behalf of Ashok Vijayakumar" <dev-bounces at shibboleth.net on behalf of ashok.vijayk at gmail.com> wrote:

>  It would be of great  help if  somebody could advice whether this approach holds good and if not holding good detailed
> explanation on disadvantages of the approach which will help us to move over to different approach for designing
> Mobile SSO.

I've already told you that it's not. ECP is meant to be used to issue SAML assertions to give to other services, not as a substitute for an authentication service that does nothing but validate credentials. It's a waste of your time to deploy Shibboleth to do something that rudimentary.

-- Scott




More information about the dev mailing list