configuration for two unrelated servers

Kevin P. Foote kpfoote at iup.edu
Fri Mar 15 13:35:15 EDT 2013


On Fri, 15 Mar 2013, Ewert, Craig wrote:

> Thanks, Kevin.  I thought from first principles that must be the case.
>
> If I only wanted SSO, and could let W handle it's own security, could I have the W app send a Shibboleth/Login to A and have A hand back the SAML assertions it got from the IdP?  In headers, or POST body or any which way?  A and W are both behind a big ole firewall in a datacenter, so I'm not worried about traffic between them.

That's not how SAML works ..from what I know.. 
(others can please correct that if it is in error)

Both A and W would be individual SPs to an Identity Provider. That gets
you the SSO and the other benefits of the underlying SAML for each
host/app.

------
thanks
  kevin.foote



More information about the users mailing list