Multi-Domain Multi-Server

Greg Zapp greg.zapp at gmail.com
Fri Jun 13 04:36:46 EDT 2014


Hi Peter,

Thanks for your help.  I'm just trying to piece it all together as this one
of the more bare topics I've encountered on the internet.  I'll set up my
own domain controller and ADFS in a lab and see if I can get it working
before bugging the guys who run the corporate installation :)

Cheers,
   -Greg


On Fri, Jun 13, 2014 at 2:00 PM, Peter Schober <peter.schober at univie.ac.at>
wrote:

> * Greg Zapp <greg.zapp at gmail.com> [2014-06-13 02:35]:
> > Hmmm, right I see.  I was under the impression, somehow, that the cookie
> > contained some verifiable information from the idP/SP required to setup
> the
> > session.  Is there no way to accomplish this without a shared SP or
> session
> > storage?
>
> Not without bouncing the browser to the IDP.
>
> > I would think that if the second, physically separate, SP sends me
> > back to the idP it would be able to see that I was already
> > authenticated and just send me back with an assertion to the second
> > ACS URL without prompting for credentials.
>
> Sure, that's what I tried to hint at before:
>
> > Due to SSO the user agent has with the SAML IDP this should not
> > cause too much effort for subjects, though.
>
> -peter
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20140613/9e487ff3/attachment.html 


More information about the users mailing list