Unsolicited (idp-initiated) Login?

Jason Walton jwalton at outbrain.com
Wed Dec 3 20:12:45 EST 2014


Well Scott -

If the service (SP) doesn't have a facility for SP-initated SAML login, and
I want to enforce SAML across my org - is there a way around providing my
users with a link of some sort to click on first?

I'm perhaps being a bit intentionally obtuse here - but if I want my users
to utilize SAML only, and the service requires unsolicited SAML - don't I
*have* to provide a link of some sort to my users? Is there any other way?
(now I'm being truly honest and asking).

Thanks!

On Wed, Dec 3, 2014 at 5:23 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:

> On 12/3/14, 9:29 PM, "Jason Walton" <jwalton at outbrain.com> wrote:
> >
> >I'm trying to work with a service that requires IDP initiated, also
> >called "unsolicited" login. There appears to be a provision in Shibboleth
> >for this via a custom crafted URL - but is there anything beyond this?
> >It's unclear to me how to deploy this to users without developing my own
> >full-featured "App Portal" ala Okta or OneLogin.
>
> I don't think "link on a page" requires an app portal, but your real
> problem is that your users will just bookmark or reenter the app URL and
> go direct. No portal fixes that.
>
> >Can someone shed some light on this for me? Or is there another open
> >source project somewhere that already exists to help implement a SAML
> >authenticated app portal or link-list for end users?
>
> I think you may be overthinking this.
>
> -- Scott
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>



-- 
Jason Walton
IT Security Manager
jwalton at outbrain.com

-- 
The above terms reflect a potential business arrangement, are provided solely 
as a basis for further discussion, and are not intended to be and do not 
constitute a legally binding obligation. No legally binding obligations will 
be created, implied, or inferred until an agreement in final form is executed 
in writing by all parties involved.

This email and any attachments hereto may be confidential or privileged. 
 If you received this communication by mistake, please don't forward it to 
anyone else, please erase all copies and attachments, and please let me 
know that it has gone to the wrong person. Thanks.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20141203/77170223/attachment.html 


More information about the users mailing list