Embedded Discovery Service and Cookie cacheExpiration

Cantor, Scott cantor.2 at osu.edu
Fri Oct 21 14:51:56 BST 2011


On 10/21/11 2:24 AM, "Dan McLaughlin" <dmclaughlin at tech-consortium.com>
wrote:

>None of our end users use more than one IdP, and there is no need to
>correct for mistakes since the DS page will continue to display until
>they've successfully authenticated to their agency.  So to continually
>show them the DS selection page doesn't make since for us.

One mistake and they're locked out unless they clear cookies.

>I'm not sure I'm following your suggestion.  Is there an example
>somewhere I can look at?

Not really. The SessionInitiator page in the docs describes all of the
plugins supported. The Cookie plugin slides in at the beginning of the
SessionInitiator chain and can automatically populate the entityID to use
based on the _saml_idp cookie that the DS sets.

For 2.4 style configs you have to manually create a 2.3-style chain since
there's none by default.

-- Scott



More information about the users mailing list