Clustering IDPs with different hostnames
Eric Goodman
ericg at ucsc.edu
Wed Feb 8 18:06:13 GMT 2012
We have a similar setup (though possibly for poor reasons), with two
different metadata files -- each with its own entity IDs defined -- running
against the same IdP installation.
For us, the authentications transfer over across the entity IDs. That is, I
log in for SP1 against IdPEntityID-A, and then I'm able to log into SP2
against IdPEntityID-B with no login challenge at the IdP. Again, there's
only one IdP, it's just accessed via two distinct entity IDs. I can't tell
from your post if this is the same situation you have, or if you actually
have two IdP installations.
--- Eric
On Wed, Feb 8, 2012 at 9:36 AM, Christopher Bland <chris at fdu.edu> wrote:
> Hello all,
>
> I am trying to propose a solution to my superiors but am unsure if it is
> possible. I would appreciate a sanity check. I have two seperate IDPs
> (IDP-A & IDP-B). Each has its own unique entity id which it uses to
> service SPs. I want to associate specific SPs with IDP-A and others with
> IDP-B, these associates are exclusive to each IDP. If IDP-A & IDP-B are
> using Terracotta to share session info. My question is this, is there any
> way for a user to go from a SP serviced by IDP-A to a SP serviced by IDP-B
> without being forced to reauthenticate because the _idp_session cookie does
> not match IDP-B's hostname and vice versa?
>
> Thanks in advance,
>
> -Chris
>
>
> --
> [image: fdu logo]
> Christopher Bland
> Systems Manager
> Information Systems and Technology
> *1000 River Road, Teaneck NJ 07666*
> Mail Stop: T-BH1-01
> [image: phone]: 201-692-2414 | [image: fax]: 201-692-2494 | [image: email]:
> chris at fdu.edu
> "Fairleigh Dickinson University will never
> ask for your password. Please do not
> share it with others!"
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20120208/7d9d3e40/attachment.html
More information about the users
mailing list