The problem with IDP initiated SSO

Christopher Bongaarts cab at umn.edu
Tue Dec 23 16:44:19 EST 2014


On 12/23/2014 3:32 PM, federator wrote:
> On 12/23/14 1:54 PM, Cantor, Scott wrote:
>>> >>We are all sinful in front of God:).  Anyhow, I see this is just an
>>> >>implementation issue.
>> >It's not. It's unimplementable.
> Apparently deep linking only works using IdP initiated SSO in Ping's
> implementation
> (http://documentation.pingidentity.com/display/SFC/SP-Initiated+SSO+via+Deep+Linking).
> We can argue how clumsy it is, but it's possible.  To many legacy
> enterprise applications, IdP initiated SSO may be the only SSO option,
> not just to Salesforce.

Note that that's not using SAML for the first step; that's a proprietary 
mechanism between Ping and Salesforce.  That's what we mean by lack of 
interoperability.

-- 
%%  Christopher A. Bongaarts   %%  cab at umn.edu          %%
%%  OIT - Identity Management  %%  http://umn.edu/~cab  %%
%%  University of Minnesota    %%  +1 (612) 625-1809    %%



More information about the users mailing list