The problem with IDP initiated SSO
federator
wpadmin at identiainc.com
Tue Dec 23 19:50:51 EST 2014
On 12/23/14 7:07 PM, Cantor, Scott wrote:
>> Apparently deep linking only works using IdP initiated SSO in Ping's
>> implementation
>> (http://documentation.pingidentity.com/display/SFC/SP-Initiated+SSO+via+De
>> ep+Linking).
> Which is not IdP-initiated SSO, QED.
The title is misleading. If you read the Note part it says:
"For deep linking to work, IdP-initiated SSO via the Authentication
Service must have been performed previously for that user. Salesforce
redirects the user only when it finds the ssostartpage cookie, which is
set only during IdP-initiated SSO via the Authentication Service."
>> We can argue how clumsy it is, but it's possible.
> It is not. Literally, it is physically impossible to do. Anything you
> think is IdP-initiated that is using a deep link (that is, starting at the
> SP end) is an SP-initiated flow with a proprietary message, and is thus
> not a standard use of SAML.
Agree that this has to be a proprietary solution of some kind, until
some company like Ping with deep pocket push it through OASIS.
>
>> To many legacy enterprise applications, IdP initiated SSO may be the only
>> SSO option,
>> not just to Salesforce.
> That doesn't make them any less buggy, and it doesn't make IdP-initiated a
> good choice, which is what the OP asked. I didn't give him the full answer
> to that question, but I think this thread did.
>
> -- Scott
>
The reason I stayed long on this thread and loved seeing so many
responses is because we do have a big client who actually wants
IdP-initiated SSO/Login to be implemented. So regardless of the
pros/cons, how well can Shibboleth handle IdP-initiated SSO? Has
anyone used this feature in a Shib-based IdP implementation?
Thanks!
Nick
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20141223/fd76fba9/attachment.html
More information about the users
mailing list