SSO with multiple Google domains

Cantor, Scott cantor.2 at osu.edu
Thu Nov 2 11:29:22 EDT 2017


> Google is suggesting using the relay state of the authentication request to
> derive domain information which can then be used to build the appropriate
> email address for the SAML response.  Is this something that can be done in
> the IdP?

You can control the RelayState if using unsolicited responses starting at the IdP, otherwise it's whatever came from the SP.

> Are there other options/recommendations?

I don't know enough about how broken their system is to really comment on what else might be possible. I think somebody needs to tell Google to fix their code.

-- Scott



More information about the users mailing list