Protecting the tomcat default page on IdP

Cantor, Scott cantor.2 at osu.edu
Thu Mar 24 09:44:36 EDT 2016


> How can I protect the base/root so that users gets access to the list of SPs
> only after authentication. After that since the user already has a session he
> can simply access all the SPs.

You can't, not with the IdP anyway.

> Essentially IdP and SP in same box.

Then you'd have to install an SP. It's not "essentially", it *is*. You install both, unless you use something else.

> Are there any guides/docs on how to achieve this ?

The SP documentation, that's it. The IdP doesn't directly enter into the conversation.

> Are there any security considerations that need to be taken care before running such setup in
> production?

Nothing new.

-- Scott



More information about the users mailing list