Advise

Sam Wilson swilsonau at gmail.com
Fri Jan 23 16:25:37 EST 2015


I second Scott's advice.

While we run two IDP to support internal and external, it is also true that we re-use our internal IDP across multiple distinct security zones so we have a single internal identity. I would recommend you don't split your identities unless they are already split for you  because of some other reason. 

Sam


> On 24 Jan 2015, at 00:27, Cantor, Scott <cantor.2 at osu.edu> wrote:
> 
> On 1/23/15, 1:42 PM, "Vilus, Luckson" <Luckson.Vilus at lacapitale.com> wrote:
> 
> 
> 
>> Do you think this the right way to go? Have you some advise to give us in 
>> that issue?
> 
> I think it's needlessly complicated. Use one IdP for both and simply 
> provide the necessary attributes to the resources, internal or external.
> 
> -- Scott
> 
> -- 
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list