Unsolicited (idp-initiated) Login?
IAM David Bantz
dabantz at alaska.edu
Wed Dec 3 16:43:00 EST 2014
Assuming the "Unsolicited" profile is enabled in your IdP at your.idp.edu,
and the SP is at https://service.com/SAML/...
you can craft a slightly ugly URL like:
https://your.idp.edu/idp/profile/SAML2/Unsolicited/SSO?providerId=https%3A%2F%2Fservice.com%2FSAML%2F.
..
As you note, you'll want to put this link behind some text or button for
users.
On Wed, Dec 3, 2014 at 12:29 PM, Jason Walton <jwalton at outbrain.com> wrote:
> Hi -
>
> I'm trying to work with a service that requires IDP initiated, also called
> "unsolicited" login. There appears to be a provision in Shibboleth for this
> via a custom crafted URL - but is there anything beyond this? It's unclear
> to me how to deploy this to users without developing my own full-featured
> "App Portal" ala Okta or OneLogin.
>
> Can someone shed some light on this for me? Or is there another open
> source project somewhere that already exists to help implement a SAML
> authenticated app portal or link-list for end users?
>
> Thanks.
>
> The above terms reflect a potential business arrangement, are provided solely
> as a basis for further discussion, and are not intended to be and do not
> constitute a legally binding obligation. No legally binding obligations will
> be created, implied, or inferred until an agreement in final form is executed
> in writing by all parties involved.
>
> This email and any attachments hereto may be confidential or privileged.
> If you received this communication by mistake, please don't forward it to
> anyone else, please erase all copies and attachments, and please let me
> know that it has gone to the wrong person. Thanks.
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20141203/c400e0e1/attachment.html
More information about the users
mailing list