Question of shibboleth deployment
Cantor, Scott
cantor.2 at osu.edu
Fri Apr 5 12:47:22 EDT 2013
On 4/5/13 11:43 AM, "dominic" <apchee.chen at gmail.com> wrote:
>
>UserA firstly access to spa.resourcea.com/xxx and authenticated by IdP-A.
>subsequently, UserA accesses to spb.resourceb.com/xxx(Protected resource).
>as UserA has authenticated by IdP-A, SP-B should must trust UserA and does
>not show a new login page again. I do not know what and how to do on SP-B
>and IdP-B sides.
The way you get access to SP-B is by having it issue a request to an IdP
of its or the user's choice. Whether that's IdP-A or -B is up to your
config or a discovery process that might ask the user which IdP to use. If
that choice is IdP-A, then there might be SSO, and if it's IdP-B, then
they might login again.
-- Scott
More information about the users
mailing list