<html>
  <head>
    <meta content="text/html; charset=ISO-8859-1"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    Scott,<br>
    <br>
    Your response challenges my understanding of what I'm trying to
    accomplish so let me ask you this.&nbsp; If I have a single SP that I
    associate with 3 IDPs is it possible to configure a DS to
    automatically validate a previous session without prompting the
    user.&nbsp; For what I am intending, I am going to set a default IDP for
    each application on the SP but want sessions from all IDPs to work.&nbsp;
    Also is there any way to specify a session hierarchy in case a user
    happens to have active sessions with more than one of the 3 IDPs?<br>
    <br>
    -Chris<br>
    <br>
    On 2/17/12 10:10 AM, Cantor, Scott wrote:
    <blockquote cite="mid:CB63D702.1594F%25cantor.2@osu.edu" type="cite">
      <pre wrap="">On 2/17/12 9:18 AM, "Christopher Bland" <a class="moz-txt-link-rfc2396E" href="mailto:chris@fdu.edu">&lt;chris@fdu.edu&gt;</a> wrote:
</pre>
      <blockquote type="cite">
        <pre wrap="">   
   I have what is probably a beginner question about SP
   SessionInitators.  Previously I have only dealt with SPs using a
   single IDP.  I have always provided Metadata for development and
   production IDPs but have not simultaneously used sessions from
   both.  It seems that all I have to do is within a
   &lt;SessionInitiator type="Chaining"&gt; tag have a series of
   individual SessionInitiator tags specifying each IDP available for
   authentication.
</pre>
      </blockquote>
      <pre wrap="">
No. Chaining the plugins is for connecting protocol initiators (SAML2,
Shib, etc.) with discovery initiators (SAMLDS) that don't have an assumed
entityID. You can't just have more than one protocol initiator with
different entityIDs, only the first one will matter. The protocol plugins
look for an entityID to use and if missing, fall through to the later
plugins. The discovery plugins run without an entityID set, and dispatch
to a page that eventually returns the client to the original location with
an entityID set, at which point the protocol plugins can run.

</pre>
      <blockquote type="cite">
        <pre wrap="">   What's unclear to me is the process of associating a user with an
   IDP.  I get that IDPs are processed in series
</pre>
      </blockquote>
      <pre wrap="">
They aren't. Or rather they are, but the later ones never get used unless
the earlier ones can't dispatch because of metadata issues (lack of
support for a given protocol).

</pre>
      <blockquote type="cite">
        <pre wrap="">but does the
   SessionInitiator only check for existing session and sends users to
   the default or DS session initiator if it doesn't find previous
   session?
</pre>
      </blockquote>
      <pre wrap="">
No. The DS session initiator is what gets used when no prior initiator has
access to an entityID to run with.

Multiple IDPs means doing discovery, or it means URL trickery to hardwire
the entityID based on the resource. It is not based on the user or by
chaining them together like that. There's no conditional logic available
to decide which one to use.

-- Scott

--
To unsubscribe from this list send an email to <a class="moz-txt-link-abbreviated" href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a>
</pre>
    </blockquote>
    <br>
    <br>
    <div class="moz-signature">-- <br>
      <meta http-equiv="Content-Type" content="text/html;
        charset=ISO-8859-1">
      <title>OIRT Signature</title>
      <style media="all" type="text/css">
        #sig{
                margin:6px 0 0 15px;
                padding:6px;
                width: 530px;
                }
        #sig .person{
                font-family:Georgia, "Times New Roman", Times, serif;
                font-size:12px;
                font-style:italic;
                color:#333333;
                font-weight: bolder;
                padding: 0 0 0 15px;
        }
                #sig .title{
                font-family:Georgia, "Times New Roman", Times, serif;
                font-size:10px;
                font-style:italic;
                color:#333333;
                padding: 0 0 0 15px;
                letter-spacing: .1em;
                line-height: 10px;
        }

        #sig .row {
                line-height:12px;
                color:#333333;
                padding-top: 13px;
                padding: 10px 0 0 15px;
                font-family: Verdana, Arial, Helvetica, sans-serif;
                font-size: 10px;
        }
        #sig .top {
                font-family:Georgia, "Times New Roman", Times, serif;
                font-size:11px;
                font-style:italic;
                color:#CC0000;
                padding:7px 0 0 0;
                font-weight: bolder;
        }
        #sig .toptwo {
                font-family:Georgia, "Times New Roman", Times, serif;
                font-size:11px;
                font-style:italic;
                color:#CC0000;
                padding-left: 120px;
                font-weight: bolder;
        }

        #sig .row a:link, .row avisited {
                color:#5CBDBF;
                text-decoration:none;
                }
        #sig .row a:over{
                color:#333333;
                border: 1px black dotted;
        }

</style>
      <div id="sig">
        <table border="0" cellpadding="0" cellspacing="0" width="100%">
          <tbody>
            <tr>
              <td valign="top" width="150"><img moz-do-not-send="false"
                  src="cid:part1.05000908.05040509@fdu.edu" alt="fdu
                  logo" height="62" width="140"></td>
              <td>
                <div class="person">Christopher Bland</div>
                <div class="title">Systems Manager<br>
                  Information Systems and Technology</div>
                <div class="row"> <strong>1000 River Road, Teaneck NJ
                    07666</strong><br>
                  Mail Stop: T-BH1-01<br>
                  <img moz-do-not-send="false"
                    src="cid:part2.03080607.02050304@fdu.edu"
                    alt="phone" height="10" width="13">: 201-692-2414 |
                  <img moz-do-not-send="false"
                    src="cid:part3.00010409.08050000@fdu.edu" alt="fax"
                    height="13" width="15">: 201-692-2494 | <img
                    moz-do-not-send="false"
                    src="cid:part4.06050802.01080706@fdu.edu"
                    alt="email" height="11" width="12">: <a
                    href="mailto:chris@fdu.edu">chris@fdu.edu</a> </div>
              </td>
            </tr>
            <tr>
              <td colspan="2">
                <div class="top">"Fairleigh Dickinson University will
                  never<br>
                  &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;ask for your
                  password. Please do not share it with others!"</div>
              </td>
            </tr>
          </tbody>
        </table>
      </div>
    </div>
  </body>
</html>