The problem with IDP initiated SSO
Cantor, Scott
cantor.2 at osu.edu
Tue Dec 23 19:07:45 EST 2014
>Apparently deep linking only works using IdP initiated SSO in Ping's
>implementation
>(http://documentation.pingidentity.com/display/SFC/SP-Initiated+SSO+via+De
>ep+Linking).
Which is not IdP-initiated SSO, QED.
>
>We can argue how clumsy it is, but it's possible.
It is not. Literally, it is physically impossible to do. Anything you
think is IdP-initiated that is using a deep link (that is, starting at the
SP end) is an SP-initiated flow with a proprietary message, and is thus
not a standard use of SAML.
>To many legacy enterprise applications, IdP initiated SSO may be the only
>SSO option,
>not just to Salesforce.
That doesn't make them any less buggy, and it doesn't make IdP-initiated a
good choice, which is what the OP asked. I didn't give him the full answer
to that question, but I think this thread did.
-- Scott
More information about the users
mailing list