IDP-initiated login
Christopher Bongaarts
cab at umn.edu
Thu Sep 17 15:17:06 UTC 2020
On 9/17/2020 9:34 AM, Steve Herrera via users wrote:
> We are running IDP3.4.4. Up until now, all of our SP authentication
> has been SP-initiated. We are working with a new SP (ADP) to try to
> get SAML configured. The issue is they are IDP-initiated login only. I
> believe they are part of a Federation where we are not.
>
> Is there a way I can get this to work without becoming part of a
> Federation?
By definition, IdP initiated SAML flows are not related to federation.
The Shib IdP supports IdP initiated flows using an SSO URL of the form
(assuming the default /idp context):
https://youridp.example.edu/idp/profile/SAML2/Unsolicited/SSO?providerId=SP_ENTITY_ID
where SP_ENTITY_ID is the entity ID of the service provider. Full docs
for IdP 3.x are here:
https://wiki.shibboleth.net/confluence/display/IDP30/UnsolicitedSSOConfiguration
--
%% Christopher A. Bongaarts %% cab at umn.edu %%
%% OIT - Identity Management %% http://umn.edu/~cab %%
%% University of Minnesota %% +1 (612) 625-1809 %%
More information about the users
mailing list