Shibboleth and multiple entry points to application
Rob Brooks
rbrooks at biz-tech-solutions.com
Wed Apr 17 10:34:59 EDT 2013
I have this working now. Thanks for all your help. It was true that the
IdP wasn't returning the RelayState because the PingFed IdP had given me an
URL endpoint for redirection that was a proprietary IdP-initiated SSO. Once
we switched the endpoint to a SAML2 endpoint Shibboleth behaved as expected.
As a result I have a much better understanding about how all of this works.
:-)
Thanks
Rob
-----Original Message-----
From: Rob Brooks [mailto:rbrooks at biz-tech-solutions.com]
Sent: Tuesday, April 16, 2013 10:07 AM
To: 'Shib Users'
Subject: RE: Shibboleth and multiple entry points to application
So I've verified that I get a SAML response from the IdP but no RelayState
... that's the problem?
-----Original Message-----
From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] On
Behalf Of Cantor, Scott
Sent: Tuesday, April 16, 2013 9:46 AM
To: Shib Users
Subject: Re: Shibboleth and multiple entry points to application
On 4/16/13 10:23 AM, "Rob Brooks" <rbrooks at biz-tech-solutions.com> wrote:
>Is this where the problem is?
No. The only problem here is the IdP. They have to return the RelayState
value to the SP, and I think you'll find from tracing the traffic that they
aren't.
-- Scott
--
To unsubscribe from this list send an email to
users-unsubscribe at shibboleth.net
More information about the users
mailing list