adfs-initiated sso to shib sp ?
Cantor, Scott
cantor.2 at osu.edu
Tue Mar 5 14:37:12 EST 2013
On 3/5/13 2:00 PM, "Tom Zeller" <tzeller at dragonacea.biz> wrote:
>With idp-initiated sso, somehow a saml authentication response from
>the idp should be posted to the saml2 http-post assertion consumer
>service url on the shibboleth sp, correct ?
Yes. The point of IdP initiated is to convince the IdP to do that since
the only way the standard defines for that is to send it a request from
the SP.
>More of an adfs question than a shib question : the user will click on
>a link that url-decodes to something like the one below, where the
>RPID parameter is the sp entityID and RelayState is the target web app
>url, correct ?
>
>https://adfs.com/adfs/ls/idpInitiatedSignon.aspx?RPID=<sp
><https://adfs.com/adfs/ls/idpInitiatedSignon.aspx?RelayState=RPID=<sp>
>entity id>&RelayState=http://webapp.sp.com
>
>Did I get this right ? close ?
Possibly; they would have to define that in their documentation as we had
to.
-- Scott
More information about the users
mailing list