Alternate SSO URL for SP

a.flanagan at surrey.ac.uk a.flanagan at surrey.ac.uk
Fri Jun 8 14:46:19 BST 2012


That's correct. We wish the VLE authentication to use an Athens/Shib login page that resembles the native VLE log in page, and general federated resources to be accessed via a generic university login page.

-----Original Message-----
From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] On Behalf Of Ian Young
Sent: 08 June 2012 14:41
To: Shib Users
Subject: Re: Alternate SSO URL for SP


On 8 Jun 2012, at 14:18, Cantor, Scott wrote:

> The SP only knows what IdP to use. That's the only thing you can give 
> to initiate a session, and from there it looks up the entity, chooses 
> the bindings you configure it with (it usually just defaults that) and 
> finds the SSO URL to use. There is no option to give it a location to use.
> That's what metadata is for.

I guess I was engaging in some sloppy thinking; it's possible to use arbitrary URLs as long as you're talking about SAML 1.1 and the Shibboleth authentication request but not if you're using SAML 2.0.

> If you want different SPs to interact with a single entityID at 
> different locations, you would in general have to supply them with 
> different metadata.

Just to clarify this a little, what it sounds like you'd want in this case is for the VLE to be fed with custom metadata for the IdP so that it would use a different SSO location.

	-- Ian





More information about the users mailing list