Federated / Social Login with Company SSO
Ilya Rumyantsev
iliggio at gmx.de
Fri Jan 5 17:05:07 UTC 2024
Hi all,
is there a way to federate user login to the company SSO (or is it planned for any near future)? It is also sometimes called social login:
User visits service -> is forwarded to shibboleth -> is Forwarded to Company SSO , user logs in -> user is redirected back to shibboleth -> redirect back to service
For the Service shibboleth acts as IDP, while for company SSO it acts as SP.
Rationale:
My company uses KC-SSO for all internal applications due to it's powerful feature set. Shibboleth is working very well with federated metadata (AFAIK the only product).
Especially with the upcomping trends for multifactor authentication it becomes less convenient for users to use multiple SSO systems (TOTP confusion).
It is also inconvenient to reimplement all the login flows and security measures in 2 systems.
Thanks,
Ilya
More information about the users
mailing list