Multi-Domain Multi-Server

Peter Schober peter.schober at univie.ac.at
Thu Jun 12 22:00:56 EDT 2014


* Greg Zapp <greg.zapp at gmail.com> [2014-06-13 02:35]:
> Hmmm, right I see.  I was under the impression, somehow, that the cookie
> contained some verifiable information from the idP/SP required to setup the
> session.  Is there no way to accomplish this without a shared SP or session
> storage?

Not without bouncing the browser to the IDP.

> I would think that if the second, physically separate, SP sends me
> back to the idP it would be able to see that I was already
> authenticated and just send me back with an assertion to the second
> ACS URL without prompting for credentials.

Sure, that's what I tried to hint at before:

> Due to SSO the user agent has with the SAML IDP this should not
> cause too much effort for subjects, though.

-peter


More information about the users mailing list