The problem with IDP initiated SSO

federator wpadmin at identiainc.com
Tue Dec 23 19:50:51 EST 2014


On 12/23/14 7:07 PM, Cantor, Scott wrote:
>> Apparently deep linking only works using IdP initiated SSO in Ping's
>> implementation
>> (http://documentation.pingidentity.com/display/SFC/SP-Initiated+SSO+via+De
>> ep+Linking).
> Which is not IdP-initiated SSO, QED.
The title is misleading.  If you read the Note part it says:
"For deep linking to work, IdP-initiated SSO via the Authentication 
Service must have been performed previously for that user. Salesforce 
redirects the user only when it finds the ssostartpage cookie, which is 
set only during IdP-initiated SSO via the Authentication Service."
>> We can argue how clumsy it is, but it's possible.
> It is not. Literally, it is physically impossible to do. Anything you
> think is IdP-initiated that is using a deep link (that is, starting at the
> SP end) is an SP-initiated flow with a proprietary message, and is thus
> not a standard use of SAML.
Agree that this has to be a proprietary solution of some kind, until 
some company like Ping with deep pocket push it through OASIS.
>
>> To many legacy enterprise applications, IdP initiated SSO may be the only
>> SSO option,
>> not just to Salesforce.
> That doesn't make them any less buggy, and it doesn't make IdP-initiated a
> good choice, which is what the OP asked. I didn't give him the full answer
> to that question, but I think this thread did.
>
> -- Scott
>
The reason I stayed long on this thread and loved seeing so many 
responses is because we do have a big client who actually wants 
IdP-initiated SSO/Login to be implemented.  So regardless of the 
pros/cons, how well can Shibboleth handle IdP-initiated SSO?   Has 
anyone used this feature in a Shib-based IdP implementation?

Thanks!

Nick

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20141223/fd76fba9/attachment.html 


More information about the users mailing list