single sign on using different IdP
Cantor, Scott
cantor.2 at osu.edu
Thu Mar 7 12:15:05 EST 2013
On 3/7/13 11:44 AM, "Qian, Yi" <yqian at ku.edu> wrote:
>
>Both old IdP and new IdP against same LDAP server, due to my limited
>Shibboleth, I would like to know is there a way that user only need to
>authentication once?
Not unless you build an authentication solution that would encompass both.
You could stick a SSO system in front of both, like CAS, Cosign, pub
cookie, etc., or build your own SSO solution. Both 1.3 and 2.x can be
customized to do authentication with a cookie such as what I did at OSU
and made available, and in theory that could be made to span both.
Basically, do a bunch of work, yes, flip a switch, no.
I would not advise transitioning the way you have either. There are more
seamless upgrade strategies, some of which are described in the wiki.
-- Scott
More information about the users
mailing list