adfs-initiated sso to shib sp ?

Marc Boorshtein mboorshtein at gmail.com
Tue Mar 5 14:49:42 EST 2013


Adfs 2.0 doesn't recognize the RelayState parameter.  You need to put the
entity id for your shib SP in the loginToRp parameter.

Thanks

Marc
On Mar 5, 2013 2:37 PM, "Cantor, Scott" <cantor.2 at osu.edu> wrote:

> On 3/5/13 2:00 PM, "Tom Zeller" <tzeller at dragonacea.biz> wrote:
>
> >With idp-initiated sso, somehow a saml authentication response from
> >the idp should be posted to the saml2 http-post assertion consumer
> >service url on the shibboleth sp, correct ?
>
> Yes. The point of IdP initiated is to convince the IdP to do that since
> the only way the standard defines for that is to send it a request from
> the SP.
>
> >More of an adfs question than a shib question : the user will click on
> >a link that url-decodes to something like the one below, where the
> >RPID parameter is the sp entityID and RelayState is the target web app
> >url, correct ?
> >
> >https://adfs.com/adfs/ls/idpInitiatedSignon.aspx?RPID=<sp
> ><https://adfs.com/adfs/ls/idpInitiatedSignon.aspx?RelayState=RPID=<sp>
> >entity id>&RelayState=http://webapp.sp.com
> >
> >Did I get this right ? close ?
>
> Possibly; they would have to define that in their documentation as we had
> to.
>
> -- Scott
>
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130305/2dea8a8e/attachment.html 


More information about the users mailing list