IDP Initialized SSO - IdPUnsolicitedSSO

Cantor, Scott cantor.2 at osu.edu
Tue Dec 11 13:30:08 EST 2012


On 12/11/12 1:03 PM, "Zmuda, Matthew R" <Matthew.R.Zmuda at td.com> wrote:

>We would now like to expand our usage of shibboleth to support IDP
>Initiated SSO scenario:

I wouldn't really do that unless you had a good reason, IdP initiated is
generally just a bad thing.
  
>User logs into some application with our IDP validating their credentials
>-         
>They now want to SSO to another application
>-         
>I would like to use IDP Initiated SSO for this

Better model: go the the second app, repeat usual flow, done.

>However I¹m a little confused with the setup. Will adding
>/SAML2/Unsolicited/SSO effect my current configuration which uses
>/SAML2/Redirect/SSO?

No.

> The last ³One caveat² statement is what concerns me.

The caveat is that it defeats requiring signed requests. Unless you're
changing defaults and requiring signed requests, then it has no impact.

> 
>Are there any sample configurations which demonstrate how IDP Initiated
>SSO would work?
>I guess what I am not understanding is how I can add in IDP initialized
>SSO to our existing configuration and what else needs to be setup aside
>form the addition to handler.xml.

Nothing else. You have to build links somewhere as documented to do the
job, that's it. You should absolutely not allow anybody other than you to
build those links or you will be establishing a permanent dependency on
this proprietary mechanism that you'll have to maintain even in the face
of wanting to change software in the future.

-- Scott




More information about the users mailing list