different authentication page

Peter Schober peter.schober at univie.ac.at
Fri Dec 5 06:12:13 EST 2014


* Michael A Grady <mgrady at unicon.net> [2014-12-05 05:45]:
> Shibboleth IdP External Authentication via CAS plugin [...]
> supports sending additional parameters to the CAS Server, such as
> the entityID of the requesting service

You'll still need to have a seperate entityIDs for each protected
resource then, turning your examples http://sp/R1 and http://sp/R2
into seperate logical Shibboleth SPs, with their own entityID,
endpoints and SAML metadata.
A SAML IDP can only differentiate protected resources based on their
entityID. So I'm assuming a CAS client inside the IDP will inherit
that limitation.
-peter


More information about the users mailing list