<div dir="ltr">Hi,<br><br><div><div class="gmail_extra"><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="ltr"><div class="gmail_extra">
Client requirement is that login forms should be part of client1/2 sites not IdP domain (only should communicate with IdP to handle authentication).</div></div></blockquote><div>…<br><blockquote style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex" class="gmail_quote">
In my opinion solution with simple login link/button (here 'client1')
would be the best (standard way to handle it), we even try to convince
client to it but unfortunately without success.<br></blockquote><br>You still haven't explained the business case surrounding the requirement, other than saying that your client wants it. <i>Why</i> do they want it? What do they hope will be accomplished by this requirement? Perhaps if you can get more details from them regarding their desires/concerns you will be better able to guide them to a solution.<br>
<br></div><div>Is it because they care about the URL? Is it because they care about the design? Is it because they want have a custom authentication they want to use instead?<br></div><div><br><blockquote style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex" class="gmail_quote">
host SSO login page on different than IdP domain only to provide user
credentials and send this data to IdP authentication engine (to store
session cookie)<br></blockquote><br></div><div>It's certainly possible to handle SSO outside of the IdP (as Peter mentioned), but I agree with others that it seems odd that have the login page in one location and then try to send credentials to the IdP. This is why I'm trying to better understand what the rationale is.<br>
<br></div><div>Regards,<br></div><div>Ian<br></div></div></div></div></div>