attaching assertion to a link to another sp?

Gene Matthews gmatthew at hitachi-cta.com
Thu Aug 22 10:51:19 EDT 2013


We will have two different sp's talking to our Idp. They way the system is being specified, users will always start at protected resources behind sp1 and at some point may click a link that will take them to a protected resource at sp2. Assuming sp1 successfully receives a security assertion from our Idp, when the use clicks a link that will take them to a resource at sp2, sp1 should attach that assertion somehow to the link to sp2, I'm thinking. Then sp2 will communicate with our Idp to verify session is still valid for the user. 

This is, at least, my thinking on how this will go. I couldn't spell SAML or shibboleth 2 months ago, so I'm pretty new to this and I am not a develper, just a sys admin type. So, my questions are: 

- does my description in the first paragraph sound reasonable and implementable with shibboleth-sp and shibboleth-idp? 

- can sp1 attach the security assertion it received from the Idp to the link over to sp2? I have developers asking me how to do that (they are just learning how to spell SAML and shibboleth also). Can anyone enlighten an non-developer on how to give guidance to developers or point me to some resources. Maybe a code example? I've done some looking but not having success. 

Thanks again for all the responses to my previous posts. 



Gene 

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130822/b57ca634/attachment-0001.html 


More information about the users mailing list