single sign on using different IdP

Cantor, Scott cantor.2 at osu.edu
Thu Mar 7 12:15:05 EST 2013


On 3/7/13 11:44 AM, "Qian, Yi" <yqian at ku.edu> wrote:
>
>Both old IdP and new IdP against same LDAP server, due to my limited
>Shibboleth, I would  like to know is there a way that user only need to
>authentication once?

Not unless you build an authentication solution that would encompass both.
You could stick a SSO system in front of both, like CAS, Cosign, pub
cookie, etc., or build your own SSO solution. Both 1.3 and 2.x can be
customized to do authentication with a cookie such as what I did at OSU
and made available, and in theory that could be made to span both.

Basically, do a bunch of work, yes, flip a switch, no.

I would not advise transitioning the way you have either. There are more
seamless upgrade strategies, some of which are described in the wiki.

-- Scott




More information about the users mailing list