IDP-initiated login

Christopher Bongaarts cab at umn.edu
Thu Sep 17 15:17:06 UTC 2020


On 9/17/2020 9:34 AM, Steve Herrera via users wrote:
> We are running IDP3.4.4. Up until now, all of our SP authentication 
> has been SP-initiated. We are working with a new SP (ADP) to try to 
> get SAML configured. The issue is they are IDP-initiated login only. I 
> believe they are part of a Federation where we are not.
>
> Is there a way I can get this to work without becoming part of a 
> Federation?

By definition, IdP initiated SAML flows are not related to federation.

The Shib IdP supports IdP initiated flows using an SSO URL of the form 
(assuming the default /idp context):

https://youridp.example.edu/idp/profile/SAML2/Unsolicited/SSO?providerId=SP_ENTITY_ID

where SP_ENTITY_ID is the entity ID of the service provider. Full docs 
for IdP 3.x are here:

https://wiki.shibboleth.net/confluence/display/IDP30/UnsolicitedSSOConfiguration

-- 
%%  Christopher A. Bongaarts   %%  cab at umn.edu          %%
%%  OIT - Identity Management  %%  http://umn.edu/~cab  %%
%%  University of Minnesota    %%  +1 (612) 625-1809    %%



More information about the users mailing list