IdP Stateless Clustering / External SSO
Derek Yuen
derek.yuen at mail.utoronto.ca
Wed Jul 18 19:57:44 EDT 2012
Hi,
Looking at the IdP Stateless Clustering article, I'm wondering:
Is it necessary to implement the CryptoTransientPrincipalConnector if my cluster of IdPs if they're configured with an external SSO (i.e. CAS/Pubcookie)?
I understand that replay detection would work just fine if the user got the same IdP.
How might the replay function be different if the user got a different IdP
[which wouldn't have the users' principals] and if the CryptoTransientPrincipalConnector was not implemented?
Thanks,
Derek
More information about the users
mailing list