Protecting the tomcat default page on IdP
Prashant Bapat
prashant at apigee.com
Thu Mar 24 01:32:21 EDT 2016
Hi,
I'm implementing a SSO based on Shibboleth IdP for a bunch of services.
Lets say my base url is https://shib.mycompany.org and IdP will be at
https://shib.mycompany.org/idp.
I want to have a simple webpage at the root/base (
https://shib.mycompany.org/) from which the user selects different SPs he
wants to go to. One of them (AWS) supports only IdP initiated login.
How can I protect the base/root so that users gets access to the list of
SPs only after authentication. After that since the user already has a
session he can simply access all the SPs.
Essentially IdP and SP in same box.
Are there any guides/docs on how to achieve this ? Are there any security
considerations that need to be taken care before running such setup in
production?
Thanks.
--Prashant
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160324/2cd04534/attachment.html>
More information about the users
mailing list