2.5.3 Sp session initiator question

Cantor, Scott cantor.2 at osu.edu
Mon Mar 2 12:42:12 EST 2015


On 3/2/15, 12:30 PM, "Mike Flynn" <shibbolethlynda at yahoo.com> wrote:
>
>Currently, on the 2.5.3 test box I am running, I enabled this config 
>(which appears to be fine):

It's not. If you comment out the <SSO> element, you won't have any 
endpoints configured for the response handling and it will break after 
somebody logs in. If you want to comment that out (which you shouldn't do, 
but you can), you have to configure every SAML endpoint for every 
SSO-related function by hand like before.

If you want to just add new SessionInitiators, you can add them like 
before, just don't comment out the SSO element.

>My question is this:  Is it possible to replace the session initiator 
>definition that I have there for /lyndaSSO with the <SSO> stanza that 
>will allow me to still use the same SP link format (i.e.

No, the built-in behavior produces an endpoint at /Login, not /InCommon. 
You can't override that easily, without changing files you don't really 
want to touch. It's better to just add your own.

-- Scott



More information about the users mailing list