Multi-Domain Multi-Server
Peter Schober
peter.schober at univie.ac.at
Thu Jun 12 22:00:56 EDT 2014
* Greg Zapp <greg.zapp at gmail.com> [2014-06-13 02:35]:
> Hmmm, right I see. I was under the impression, somehow, that the cookie
> contained some verifiable information from the idP/SP required to setup the
> session. Is there no way to accomplish this without a shared SP or session
> storage?
Not without bouncing the browser to the IDP.
> I would think that if the second, physically separate, SP sends me
> back to the idP it would be able to see that I was already
> authenticated and just send me back with an assertion to the second
> ACS URL without prompting for credentials.
Sure, that's what I tried to hint at before:
> Due to SSO the user agent has with the SAML IDP this should not
> cause too much effort for subjects, though.
-peter
More information about the users
mailing list