IDP initiated SSO
Susan Forr
susan_forr at hotmail.com
Tue Aug 7 13:58:34 EDT 2012
I did read those two docs when I started with SAML. Maybe I
am still missing to understand some piece and put it all together. That is why
your help is so important.
User logs in to my App (App1) and is authenticated by some
mechanism. Till this point we don’t care what mechanism is used.
Let me focus on the part when user clicks the link to a web
application (App2) that is protected by saml: When this happens App1 will
somehow map the logged in user and get the credentials for App2 (which is
different from the login credentials used for App1). Now App1 will send the
credentials for App2 to the Shibboleth IDP. (This is what I need to implement). I want the IDP to create a SAML assertion
and send it to the SP.
So my question is: what classes/package do I need to use
from the Shibboleth IDP to send the credentials and attributes to the IDP? Is
this more of a developer community question because I will be developing a
layer over the Shibboleth IDP to send these credentials?
Thanks for your help. Your guidance will help me understand
SAML and Shibboleth IDP better.
From: paul.hethmon at clareitysecurity.com
To: users at shibboleth.net
Subject: Re: IDP initiated SSO
Date: Tue, 7 Aug 2012 00:35:17 +0000
Susan,
I'd recommend some reading material to help you understand better what SAML does as an SSO protocol:
OASIS SAML Committee: http://www.oasis-open.org/committees/tc_home.php?wg_abbrev=security
Executive Overview: http://www.oasis-open.org/committees/download.php/13525/sstc-saml-exec-overview-2.0-cd-01-2col.pdf
Technical Overview: http://www.oasis-open.org/committees/download.php/27819/sstc-saml-tech-overview-2.0-cd-02.pdf
Definitely read the executive overview, it's only about 8 pages.
thanks,
Paul
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20120807/917b9cdc/attachment.html
More information about the users
mailing list