IDP Initialized SSO - IdPUnsolicitedSSO
Zmuda, Matthew R
Matthew.R.Zmuda at td.com
Tue Dec 11 13:03:23 EST 2012
Today our IDP application is setup with shibboleth IDP to accept a request for authentication from a service provider and send SAML payload back with a response (once user has authenticated).
We would now like to expand our usage of shibboleth to support IDP Initiated SSO scenario:
- User logs into some application with our IDP validating their credentials
- They now want to SSO to another application
- I would like to use IDP Initiated SSO for this
I have read over https://wiki.shibboleth.net/confluence/display/SHIB2/IdPUnsolicitedSSO
However I'm a little confused with the setup. Will adding /SAML2/Unsolicited/SSO effect my current configuration which uses /SAML2/Redirect/SSO? The last "One caveat" statement is what concerns me.
Are there any sample configurations which demonstrate how IDP Initiated SSO would work?
I guess what I am not understanding is how I can add in IDP initialized SSO to our existing configuration and what else needs to be setup aside form the addition to handler.xml.
Thanks.
Matt Zmuda | IT Solutions Developer
DCTS Online Channels - Authentication and Security - CIP/ESR
380 Wellington St 10th Flr London | 519-667-6052
NOTICE: Confidential message which may be privileged. Unauthorized use/disclosure prohibited. If received in error, please go to www.td.com/legal for instructions.
AVIS : Message confidentiel dont le contenu peut être privilégié. Utilisation/divulgation interdites sans permission. Si reçu par erreur, prière d'aller au www.td.com/francais/avis_juridique pour des instructions.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20121211/089e0334/attachment.html
More information about the users
mailing list