IdP Discovery

Mulchek, Paul mulchekp at wustl.edu
Tue Oct 9 12:03:18 EDT 2018


We have a need to allow users to select what IdP they would like to authenticate with. We currently point SP's to our ADFS instance, as we have it configured with Home Realm Discovery, if an application would like users from our affiliated hospitals directory and our school directory. We would like to get rid of the ADFS dependency. Our current model is SP initiated sso.


I have tested the embedded discovery service and find that it works well with Shibboleth SP's but I am unsure of how to get this to work with other external applications that do not use the Shib SP software.


Other options would be to have the SP's provide links on their site for each IdP to log into. We could also create a portal page and move to IdP initiated sso but we would rather not go that route.


Any other thoughts on the preferred way to accomplish IdP picking?


Thanks,

Paul




________________________________
The materials in this message are private and may contain Protected Healthcare Information or other information of a sensitive nature. If you are not the intended recipient, be advised that any unauthorized use, disclosure, copying or the taking of any action in reliance on the contents of this information is strictly prohibited. If you have received this email in error, please immediately notify the sender via telephone or return mail.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20181009/c80062fa/attachment.html>


More information about the users mailing list