Alternate SSO URL for SP
a.flanagan at surrey.ac.uk
a.flanagan at surrey.ac.uk
Fri Jun 8 12:28:06 BST 2012
So the key to being recognised (i.e. to maintain the valid, authenticated browser session and allow instant access to federated resources) is the entity ID, and the SSO endpoint is something that only the IdP is concerned with?
From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] On Behalf Of Ian Young
Sent: 08 June 2012 12:24
To: Shib Users
Subject: Re: Alternate SSO URL for SP
On 8 Jun 2012, at 12:14, <a.flanagan at surrey.ac.uk<mailto:a.flanagan at surrey.ac.uk>> wrote:
A thought had crossed my mind that if we had 2 endpoints (or the need for two entity Ids or metadata URLs) then this would cause a problem in terms of being recognised across the federation.
Two SSO endpoints at the IdP doesn't sound like it should be a problem, as long as the IdP software you're using can do that (I'm not personally familiar with it). The endpoint you choose to advertise in federation metadata would be the generic one rather than the special one, of course.
I wouldn't suggest going down the multiple entity ID route for your IdP if you can avoid it.
-- Ian
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20120608/59612ee5/attachment.html
More information about the users
mailing list