Shibboleth Service Provider in Federation with OpenAM Policy Agent results in Single Sign On Bug
Peter Schober
peter.schober at univie.ac.at
Fri Oct 12 17:13:40 EDT 2012
* David Purdy <daveprdy at gmail.com> [2012-10-12 22:39]:
> 1: Browse to the application protected by the Policy Agent (but don't log
> in).
>
> 2: Browse to the application protected by Shibboleth (but don't log in).
>
> 3: Log into the application protected by the Policy Agent.
>
> After completing step 3 above, when you click "Login", the URL changes to
> http://openam-url:8080/openam/UI/Login. Then when you click "Login" again,
> the users OpenAM profile is displayed instead of the desired
> application.
None of the things you say are sufficiently specific to say anything,
really. I have no idea how OpenAM's "Policy Agent" works (nor is this
the place to discuss) and sentences 1-3 make no sense to me whatsoever
(with SAML WebSSO you'd always log in to the SAML IdP, not an
application or "Agent").
Do you mean you get redirected to a SAML IdP after each of the steps
1-3, and then interrupt that flow and go back to the application
without logging in at the IdP?
All of this sounds very much like a question for an OpenAM forum (it's
OpenAM where you end up in the wrong place?), even though you write
"Bug" in your subject to the Shibboleth users list but provide no
technical evidence for that.
-peter
More information about the users
mailing list