IdPUnsolicitedSSO
Tom Scavo
trscavo at gmail.com
Tue Jul 3 16:16:19 EDT 2012
On Tue, Jul 3, 2012 at 3:51 PM, Chu, Man Sin
<ManSin.Chu at alliancebernstein.com> wrote:
>
>I am looking to have this
> workflow implemented and wondering if this is exactly what IdPUnsolicitedSSO
> described to be
>
> Identity Provider (via any "non-Shibboleth" SAML provider,
> like PingFederate) --> SAML Response --> Service Provider (via Shibboleth)
>
> Is there a sample configuration for IdPUnsolicitedSSO that I can take a
> look?
FWIW, the SimpleSAMLphp IdP can do IdP-initiated SSO. Don't know about
other non-Shibboleth IdPs.
Just so you know, in the eyes of the SP, IdP-initiated SSO is less
secure than SP-initiated SSO. An attacker that gets its hands on the
IdP's private signing key (by whatever means) can push SSO assertions
to SPs at will. An SP can force an attacker to compromise the IdP
itself (which presumably is more difficult) by requiring RelayState
and/or HTTP-Artifact.
Tom
More information about the users
mailing list