IdPUnsolicitedSSO
Paul Hethmon
paul.hethmon at clareitysecurity.com
Tue Jul 3 17:13:06 EDT 2012
If you check the list archives, you can find links to a JSP page you can
put on the IdP to create an SP AuthnRequest to submit to the IdP and thus
end up with IdP initiated flow.
Paul
On 7/3/12 4:16 PM, "Tom Scavo" <trscavo at gmail.com> wrote:
>On Tue, Jul 3, 2012 at 3:51 PM, Chu, Man Sin
><ManSin.Chu at alliancebernstein.com> wrote:
>>
>>I am looking to have this
>> workflow implemented and wondering if this is exactly what
>>IdPUnsolicitedSSO
>> described to be
>>
>> Identity Provider (via any "non-Shibboleth" SAML
>>provider,
>> like PingFederate) --> SAML Response --> Service Provider (via
>>Shibboleth)
>>
>> Is there a sample configuration for IdPUnsolicitedSSO that I can take a
>> look?
>
>FWIW, the SimpleSAMLphp IdP can do IdP-initiated SSO. Don't know about
>other non-Shibboleth IdPs.
>
>Just so you know, in the eyes of the SP, IdP-initiated SSO is less
>secure than SP-initiated SSO. An attacker that gets its hands on the
>IdP's private signing key (by whatever means) can push SSO assertions
>to SPs at will. An SP can force an attacker to compromise the IdP
>itself (which presumably is more difficult) by requiring RelayState
>and/or HTTP-Artifact.
>
>Tom
>--
>To unsubscribe from this list send an email to
>users-unsubscribe at shibboleth.net
More information about the users
mailing list