Shibboleth Authentication request flow

David Gersic dgersic at niu.edu
Thu Dec 18 09:27:53 EST 2014


Shibboleth is an implementation of SAML. So if you understand how SAML works, you understand what Shibboleth is doing. Start here for basic SAML description:


http://en.wikipedia.org/wiki/Security_Assertion_Markup_Language


https://blog.surfnet.nl/?p=1417




________________________________
From: users-bounces at shibboleth.net <users-bounces at shibboleth.net> on behalf of Sathish Anickode <SAnickode at skytouchtechnology.com>
Sent: Wednesday, December 17, 2014 9:02 PM
To: Shib Users
Subject: Shibboleth Authentication request flow

I would like to understand how the authentication request flows between the user's browser, SP and IdP.

A user accesses a resource on a SP for the first time and since there is no associated authenticated session, a SAML request is sent to the IdP to authenticate the user. Since the user does not have an associated session on the IdP, does the IdP send back a SAML response requesting the user to be redirected to the login page? Can you please clarify how this interaction works?

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20141218/b8b6ca33/attachment.html 


More information about the users mailing list