different authentication page
Michael A Grady
mgrady at unicon.net
Fri Dec 5 17:49:50 EST 2014
On Dec 5, 2014, at 5:12 AM, Peter Schober <peter.schober at univie.ac.at> wrote:
> * Michael A Grady <mgrady at unicon.net> [2014-12-05 05:45]:
>> Shibboleth IdP External Authentication via CAS plugin [...]
>> supports sending additional parameters to the CAS Server, such as
>> the entityID of the requesting service
>
> You'll still need to have a seperate entityIDs for each protected
> resource then, turning your examples http://sp/R1 and http://sp/R2
> into seperate logical Shibboleth SPs, with their own entityID,
> endpoints and SAML metadata.
> A SAML IDP can only differentiate protected resources based on their
> entityID. So I'm assuming a CAS client inside the IDP will inherit
> that limitation.
> -peter
>
Indeed, you'd really need to have distinct entityIDs.
--
Michael A. Grady
Senior IAM Consultant, Unicon, Inc.
More information about the users
mailing list