IdPUnsolicitedSSO

Tom Scavo trscavo at gmail.com
Tue Jul 3 16:16:19 EDT 2012


On Tue, Jul 3, 2012 at 3:51 PM, Chu, Man Sin
<ManSin.Chu at alliancebernstein.com> wrote:
>
>I am looking to have this
> workflow implemented and wondering if this is exactly what IdPUnsolicitedSSO
> described to be
>
>                 Identity Provider (via any "non-Shibboleth" SAML provider,
> like PingFederate) --> SAML Response --> Service Provider (via Shibboleth)
>
> Is there a sample configuration for IdPUnsolicitedSSO that I can take a
> look?

FWIW, the SimpleSAMLphp IdP can do IdP-initiated SSO. Don't know about
other non-Shibboleth IdPs.

Just so you know, in the eyes of the SP, IdP-initiated SSO is less
secure than SP-initiated SSO. An attacker that gets its hands on the
IdP's private signing key (by whatever means) can push SSO assertions
to SPs at will. An SP can force an attacker to compromise the IdP
itself (which presumably is more difficult) by requiring RelayState
and/or HTTP-Artifact.

Tom


More information about the users mailing list