Joint SP configuration for two applications- attributePrefix conflict
Klingenstein, Nate
nklingenstein at calstate.edu
Mon Nov 28 20:52:29 EST 2016
> It isn't a Shibboleth feature, it's a SAML feature.
Assuming a competent and compliant implementation, which, well.
The other caveat is that this doesn't scale well for lots of identity providers. If the old central discovery service(or XAuth, if you want cobwebs)
https://groups.google.com/forum/#!topic/diso-project/LGy23MtZnxo
were the solution, I feel like we wouldn't have abandoned that.
I still prefer the single entityID approach personally and I think the response you got was spot on:
"I've never heard of this passive login feature of Shibboleth. It sounds nice, and it sounds like what single sign on promises, which is the ability to log in once and then be logged in to various applications such as Dataverse and your Drupal application."
If there were a central token registry of some sort, then I would hold out some hope.
More information about the users
mailing list