Alternate SSO URL for SP
a.flanagan at surrey.ac.uk
a.flanagan at surrey.ac.uk
Fri Jun 8 14:46:19 BST 2012
That's correct. We wish the VLE authentication to use an Athens/Shib login page that resembles the native VLE log in page, and general federated resources to be accessed via a generic university login page.
-----Original Message-----
From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] On Behalf Of Ian Young
Sent: 08 June 2012 14:41
To: Shib Users
Subject: Re: Alternate SSO URL for SP
On 8 Jun 2012, at 14:18, Cantor, Scott wrote:
> The SP only knows what IdP to use. That's the only thing you can give
> to initiate a session, and from there it looks up the entity, chooses
> the bindings you configure it with (it usually just defaults that) and
> finds the SSO URL to use. There is no option to give it a location to use.
> That's what metadata is for.
I guess I was engaging in some sloppy thinking; it's possible to use arbitrary URLs as long as you're talking about SAML 1.1 and the Shibboleth authentication request but not if you're using SAML 2.0.
> If you want different SPs to interact with a single entityID at
> different locations, you would in general have to supply them with
> different metadata.
Just to clarify this a little, what it sounds like you'd want in this case is for the VLE to be fed with custom metadata for the IdP so that it would use a different SSO location.
-- Ian
More information about the users
mailing list