IDP Initialized SSO - IdPUnsolicitedSSO

Zmuda, Matthew R Matthew.R.Zmuda at td.com
Tue Dec 11 13:03:23 EST 2012


Today our IDP application is setup with shibboleth IDP to accept a request for authentication from a service provider and send SAML payload back with a response (once user has authenticated).

We would now like to expand our usage of shibboleth to support IDP Initiated SSO scenario:

-          User logs into some application with our IDP validating their credentials

-          They now want to SSO to another application

-          I would like to use IDP Initiated SSO for this

I have read over https://wiki.shibboleth.net/confluence/display/SHIB2/IdPUnsolicitedSSO
However I'm a little confused with the setup. Will adding /SAML2/Unsolicited/SSO effect my current configuration which uses /SAML2/Redirect/SSO? The last "One caveat" statement is what concerns me.

Are there any sample configurations which demonstrate how IDP Initiated SSO would work?
I guess what I am not understanding is how I can add in IDP initialized SSO to our existing configuration and what else needs to be setup aside form the addition to handler.xml.

Thanks.


Matt Zmuda | IT Solutions Developer
DCTS Online Channels - Authentication and Security - CIP/ESR
380 Wellington St 10th Flr London | 519-667-6052


NOTICE: Confidential message which may be privileged. Unauthorized use/disclosure prohibited. If received in error, please go to www.td.com/legal for instructions.
AVIS : Message confidentiel dont le contenu peut être privilégié. Utilisation/divulgation interdites sans permission. Si reçu par erreur, prière d'aller au www.td.com/francais/avis_juridique pour des instructions.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20121211/089e0334/attachment.html 


More information about the users mailing list