You(Nate, Scott &amp; Peter) are doing great job for all our doubts and queries with a lot of patience, Thanks a lot to you all once again......:)<div><br></div><div>Finally we are succeeded our requirement in implementation of SAML on our site....now we are going to implement it on our production servers so kindly share your valuable suggestions to avoid security breaches / necessary things to do before implementing SAML on production servers.</div>

<div><br></div><div>- Raja.<br><div class="gmail_extra"><br><br><div class="gmail_quote">On Fri, Nov 2, 2012 at 2:05 PM, Peter Schober <span dir="ltr">&lt;<a href="mailto:peter.schober@univie.ac.at" target="_blank">peter.schober@univie.ac.at</a>&gt;</span> wrote:<br>


<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);border-left-style:solid;padding-left:1ex">* Raz&#39;s &lt;<a href="mailto:gajula.rajashekhar@gmail.com" target="_blank">gajula.rajashekhar@gmail.com</a>&gt; [2012-11-01 19:15]:<br>



<div>&gt; For us, sessions should be separate for the vhosts (dev &amp; test) even if<br>
&gt; they are registered at the same IDP so what do you suggest to over come the<br>
&gt; above scenario?<br>
<br>
</div>What kind of real-world set up are you perparing for that requires all<br>
users to use the same instance of a webbrowser on the same machine,<br>
with an active session to the IdP? It&#39;s far from a common scenario to<br>
have several users share the same HTTP User Agent at the same time.<br>
<br>
If you want to test several users accessing your apps and sharing the<br>
same IdP a more realistic scenario (and one which would actually work)<br>
is using two seperate HTTP User Agents (or one in &quot;private&quot; browsing<br>
mode, not sharing state with the other).<br>
<br>
Also you&#39;re trying to achieve many things at once (without fully<br>
understanding them, it seems) and mixing them all into an existing,<br>
rather confused thread:<br>
User switching in the same browser is one thing, forced authentication<br>
another. As is configuring your webserver and SAML metadata for one<br>
vhost per &quot;customer&quot;. Logout yet another. (I&#39;m sure I left out a few.)<br>
I&#39;d concentrate on one thing at a time, and make that work. Them move<br>
on to the next one,<br>
-peter<br>
<div><div>--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br></div>
</div>