Questions starting to implement Shibboleth IDP

Robert Law robert at solutionreach.com
Wed Dec 31 15:09:25 EST 2014


Are the web user's cookies available to the authentication mechanism?  If
they are then it would be fairly easy to determine that they have already
logged on.

On Wed, Dec 31, 2014 at 1:05 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:

> > It probably is covered.
>
> Assuming Chris accurately understood the goal, no, the standard certainly
> doesn't cover that. Making it the private business of an authentication
> mechanism at the IdP is one way of doing something like that.
>
> -- Scott
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20141231/5d9e050f/attachment.html 


More information about the users mailing list