Federated / Social Login with Company SSO

Ilya Rumyantsev iliggio at gmx.de
Fri Jan 5 17:05:07 UTC 2024


Hi all,

is there a way to federate user login to the company SSO (or is it planned for any near future)? It is also sometimes called social login:

User visits service -> is forwarded to shibboleth -> is Forwarded to Company SSO , user logs in -> user is redirected back to shibboleth -> redirect back to service

For the Service shibboleth acts as IDP, while for company SSO it acts as SP.


Rationale:

My company uses KC-SSO for all internal applications due to it's powerful feature set. Shibboleth is working very well with federated metadata (AFAIK the only product).

Especially with the upcomping trends for multifactor authentication it becomes less convenient for users to use multiple SSO systems (TOTP confusion).
It is also inconvenient to reimplement all the login flows and security measures in 2 systems.


Thanks,
Ilya


More information about the users mailing list