IdP Stateless Clustering / External SSO

Derek Yuen derek.yuen at mail.utoronto.ca
Wed Jul 18 19:57:44 EDT 2012


Hi,

Looking at the IdP Stateless Clustering article, I'm wondering:
   Is it necessary to implement the CryptoTransientPrincipalConnector if my cluster of IdPs if they're configured with an external SSO (i.e. CAS/Pubcookie)?

I understand that replay detection would work just fine if the user got the same IdP.
How might the replay function be different if the user got a different IdP 
[which wouldn't have the users' principals] and if the CryptoTransientPrincipalConnector was not implemented?




Thanks,
Derek


More information about the users mailing list