How can an SP send extra information to the IdP

Bogdan Albei bogdan.albei at callsign.com
Fri Jan 8 08:12:01 EST 2016


That is true, but we are integrating with certain SPs, such as Office 365,
for multiple customers.  We need to know, as part of our workflow, on
behalf of which customer the authorisation is requested. Identifying by
entity id won't work because of the one-to-many relationship between the SP
and the customers on behalf of which we integrate with that SP.

On 8 January 2016 at 12:51, Tom Scavo <trscavo at internet2.edu> wrote:

> On Fri, Jan 8, 2016 at 4:43 AM, Bogdan Albei <bogdan.albei at callsign.com>
> wrote:
> >
> > We are an IdP that integrates with various SPs on behalf of our
> customers.
> > Let's say we have customer A and customer B that both want us to act as
> an
> > IdP and provide authentication for Office 365. The problem is when we
> > receive a SAML request from Office 365(the SP). At that point we need to
> > know if that request is made on behalf of customer A or customer B. How
> > could the SP send that extra information?
>
> The SAML AuthnRequest contains the globally unique entityID of the SP
> making the request (or more accurately, the SP wishing a response). So
> no "extra information" is needed.
>
> Tom
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>



-- 
Bogdan Albei
Senior Platform Engineer
Callsign Inc.
[C] bogdan
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160108/2c347c49/attachment.html>


More information about the users mailing list