Alternate SSO URL for SP

a.flanagan at surrey.ac.uk a.flanagan at surrey.ac.uk
Fri Jun 8 12:14:39 BST 2012


Thanks Ian

A thought had crossed my mind that if we had 2 endpoints (or the need for two entity Ids or  metadata URLs) then this would cause a problem in terms of being recognised across the federation. The reason for our complex requirements is so that once a user signs in to our VLE they can then access other protected resources without needing to sign in again. Also, we want the alternate SSO URL so that we can brand it to appear the same as our native VLE login page, thus creating a seamless and graceful failover in the event of downtime or failure of our IdP.

From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] On Behalf Of Ian Young
Sent: 08 June 2012 12:01
To: Shib Users
Subject: Re: Alternate SSO URL for SP


On 8 Jun 2012, at 11:36, <a.flanagan at surrey.ac.uk<mailto:a.flanagan at surrey.ac.uk>> wrote:


Can we provide this alternate SSO URL using a <SessionInitiator> in the shibboleth2.xml file on our VLE,

Yes (Chad had the details).


or must the SSO URL be provided within the IdP metadata?

I am fairly sure the IdP SSO URLs that you configure into the SP's SessionInitiators do not need to appear in the IdP's metadata.

In addition, think I recall that we verify that the IdP only has one SSO endpoint for any given binding, so that discovery services aren't going to get confused.  So, we wouldn't accept registration of additional ones (for the same binding) anyway.

                -- Ian

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20120608/d48a4573/attachment.html 


More information about the users mailing list