The problem with IDP initiated SSO

Cantor, Scott cantor.2 at osu.edu
Tue Dec 23 19:07:45 EST 2014


>Apparently deep linking only works using IdP initiated SSO in Ping's
>implementation 
>(http://documentation.pingidentity.com/display/SFC/SP-Initiated+SSO+via+De
>ep+Linking).

Which is not IdP-initiated SSO, QED.

> 
>We can argue how clumsy it is, but it's possible.

It is not. Literally, it is physically impossible to do. Anything you 
think is IdP-initiated that is using a deep link (that is, starting at the 
SP end) is an SP-initiated flow with a proprietary message, and is thus 
not a standard use of SAML.

>To many legacy enterprise applications, IdP initiated SSO may be the only 
>SSO option,
>not just to Salesforce.

That doesn't make them any less buggy, and it doesn't make IdP-initiated a 
good choice, which is what the OP asked. I didn't give him the full answer 
to that question, but I think this thread did.

-- Scott



More information about the users mailing list