embedding IdP's login page (Banner AppNav)

Rob Gorrell rwgorrel at uncg.edu
Tue Sep 20 11:48:21 EDT 2016


This seems like a conceptually bad idea and counter to some of the core
principles of SSO like maintaining control over the login process... as
such, I would hazard its common practice for many of us to disallow this by
setting the X-Frame-Options DENY header?

But if that is the common practice, how do you approach the inevitable
exception? the app that must place your IdP's login page inside a frame
without completely opening up for any app to do so?

Like many of you I'm sure, we're struggling to get a grasp on Banner XE's
SSO requirements. One area we've butted up against this Banner XE's new
Application Navigator.. an SP/app thats intended to launch other Banner XE
SP's inside frames... behavior which our IdP doesn't allow. We've rejected
one or two requests in the past for smaller outside apps wanting to do
this, but Banner AppNav is not something that will go away or is likely to
change.

So knowing we aren't unique in tackling Banner XE as well as generally
stopping our IdP page from being embedded, is there a compromise in this
sort of situation?

-Rob

-- 
Robert W. Gorrell
Systems Architect, Identity and Access Management
University of NC at Greensboro
336-334-5954
PGP Key ID B36DB0CA
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160920/1e246540/attachment-0001.html>


More information about the users mailing list