<p>Adfs 2.0 doesn't recognize the RelayState parameter. You need to put the entity id for your shib SP in the loginToRp parameter.</p><p>Thanks</p><p>Marc</p>
<div class="gmail_quote">On Mar 5, 2013 2:37 PM, "Cantor, Scott" <<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>> wrote:<br type="attribution"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
On 3/5/13 2:00 PM, "Tom Zeller" <<a href="mailto:tzeller@dragonacea.biz" target="_blank">tzeller@dragonacea.biz</a>> wrote:<br>
<br>
>With idp-initiated sso, somehow a saml authentication response from<br>
>the idp should be posted to the saml2 http-post assertion consumer<br>
>service url on the shibboleth sp, correct ?<br>
<br>
Yes. The point of IdP initiated is to convince the IdP to do that since<br>
the only way the standard defines for that is to send it a request from<br>
the SP.<br>
<br>
>More of an adfs question than a shib question : the user will click on<br>
>a link that url-decodes to something like the one below, where the<br>
>RPID parameter is the sp entityID and RelayState is the target web app<br>
>url, correct ?<br>
><br>
><a href="https://adfs.com/adfs/ls/idpInitiatedSignon.aspx?RPID=" target="_blank">https://adfs.com/adfs/ls/idpInitiatedSignon.aspx?RPID=</a><sp<br>
><<a href="https://adfs.com/adfs/ls/idpInitiatedSignon.aspx?RelayState=RPID=" target="_blank">https://adfs.com/adfs/ls/idpInitiatedSignon.aspx?RelayState=RPID=</a><sp><br>
>entity id>&RelayState=<a href="http://webapp.sp.com" target="_blank">http://webapp.sp.com</a><br>
><br>
>Did I get this right ? close ?<br>
<br>
Possibly; they would have to define that in their documentation as we had<br>
to.<br>
<br>
-- Scott<br>
<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>