Shibboleth Service Provider Configuration for Single app for?multiple sub domains with Different IDP's

William Spooner william.spooner at eaglegenomics.com
Sun Oct 28 19:11:40 EDT 2012


This is a pretty common model with, for example, Google apps marketplace,
notably Atlassian OD. To put some flesh on the bones, if you have a
shib-protected apache vhost that responds to *.myapp.org, how do you direct
requests to cust1.myapp.org to the correct IdP entityid with the correct
target (e.g.
https://myapp.org/Shibboleth/Login?EntityID=https:cust1.org/idp/login&target=https:cust1.myapp.org/lastpage)
at session initiation? Once you get past this step, everything 'just works'
in my experience.

An aside, Atlassian have a basic discovery service for their customer
subdomain login; Google or orphan. Not great, but not hard-coded to a
single IdP either.

Best,

Will
On Oct 28, 2012 8:33 PM, "Peter Schober" <peter.schober at univie.ac.at> wrote:

> * Randy Wiemer <wiemerr at hotmail.com> [2012-10-28 04:04]:
> > The counter example is Sales Force which uses a feature they call
> > “My Domains”, which is a subdomain per customer, to handle the IdP
> > discovery process.
>
> It doesn't handle IDP discovery. You'll need to know the specific
> entry point into the service from somewhere else (which hardcodes the
> IdP, practically), instead of the subject just going to Service A and
> selecting where to log in,
> -peter
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20121028/1f7469f5/attachment.html 


More information about the users mailing list