<div dir="ltr">Hi Team, <div><br></div><div>On my project we are  making POC for Mobile Single Sign on, the technology stack as below, </div><div><br></div><div>Identity Provider - Shibboleth {Authentication of user with JAAS Module }</div><div><br></div><div>Service Provider - Amazon Web service will be hosting our REST Services.</div><div><br></div><div>We decided to  authenticate the users of Mobile Application using Shibboleth ECP end point.</div><div><br></div><div>We will  configure the IdP Session time out to the 6 months.</div><div><br></div><div>After the user being authenticated with Shibboleth ECP end point  for the first time with the user name and password , the subsequent authentication will be via shibboleth cookie received during first authentication. </div><div><br></div><div>We are planning to make this subsequent authentication requests with the Shibboleth Cookie until the IdP Session expiry time.</div><div><br></div><div>It would be of great  help if  somebody could advice whether this approach holds good and if not holding good detailed explanation on disadvantages of the approach which will help us to move over to different approach for designing Mobile SSO.</div><div><br></div><div>Thanks,</div><div>Ashok Vijayakumar.</div><div><br></div><div><br></div><div><br></div><div><br></div></div>