HA IDPs stateless behind load balancer with authentication via CAS
Cantor, Scott
cantor.2 at osu.edu
Thu Dec 12 19:18:39 EST 2013
On 12/12/13, 7:14 PM, "Ted Fisher" <tffishe at bgsu.edu> wrote:
>It seems that there would be minimal impact if an IDP failed and all
>requests went to the other IDP since that IDP would depend on CAS for the
>SSO session. The only impact would be on authentications that are in
>process when an IDP dies in which case they would need to try again
>(should be few so easily acceptable).
Yes, pretty much.
>We are not trying to use SLO. We simply have all logout URLs call our
>central logout URL which then calls to each known service that we provide
>(sloppy but
> effective).
Does that work without third party cookies?
>
>Am I missing something?
>Is there any other factor to take into account for this?
Well, if you have a need for attribute query for legacy reasons or some
other reason, you need to configure alternate plugins to support that kind
of transient NameID, but that's about it.
-- Scott
More information about the users
mailing list