Understanding flow / federation

Cantor, Scott cantor.2 at osu.edu
Mon Sep 24 13:48:27 EDT 2012


On 9/24/12 1:42 PM, "Bo Lorentsen" <bl at moch.dk> wrote:
>>Then you already have IdPs. You don't need to add one.

>> 
>I have another company, that have a large MS AD full of users that likes
>to use some of our services without login, I dare to believe this is
>called SSO.

They have to login at some point. SSO involves multiple services and
whether you have to login again or not in between. The base case of one
service is just federated authentication. In that model, the users'
organization runs an IdP and you run an SP.

What you're doing is looking at a deployment model involving additional
intermediaries. Some people think that's unneeded and some people that
they're completely necessary to effectively manage federated access.

-- Scott




More information about the users mailing list