SingleSignOnService
Tom Scavo
trscavo at gmail.com
Mon Dec 5 12:22:46 EST 2016
On Mon, Dec 5, 2016 at 10:31 AM, Sam Jacob <skjacob at gmail.com> wrote:
> thanks, Scott.
Scott gave one answer. I'll offer another.
> This's the first time we are having an IDP-initiated SSO signing in.
It may have occurred before and you may not even have noticed it. To
illustrate, if you point me to your SP metadata (which is presumably
online), I'll try to log in by pushing a SAML assertion to your SP
(assuming you trust one of my IdPs).
> Are there any other configurations in Shib SP that we need to add or update
> to get it to work. Any documentation pointers will be helpful too.
On the SP side, no, there is nothing you need to do. For any IdP for
which you have exchanged metadata, that IdP should be able to push a
SAML assertion to your SP. How the IdP accomplishes that is
proprietary (as Scott pointed out) but that's not really anything you
need to be concerned about.
Tom
> On Mon, Dec 5, 2016 at 9:18 AM, Cantor, Scott <cantor.2 at osu.edu> wrote:
>>
>> On 12/5/16, 10:09 AM, "users on behalf of Sam Jacob"
>> <users-bounces at shibboleth.net on behalf of skjacob at gmail.com> wrote:
>>
>> > what they are saying is , they will be doing a IDP initiated SSO and
>> > therefore no need for SingleSignOnService
>> > attribute.
>> > Is this the case?
>>
>> Technically, but that means you're going to have to dummy up something.
>>
>> -- Scott
>>
>>
>>
>> --
>> To unsubscribe from this list send an email to
>> users-unsubscribe at shibboleth.net
>
>
>
>
> --
> Sam Jacob
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
More information about the users
mailing list