<div dir="ltr">Hi,<br><br><div><div class="gmail_extra"><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="ltr"><div class="gmail_extra">
Client requirement is that login forms should be part of client1/2 sites not IdP domain (only should communicate with IdP to handle authentication).</div></div></blockquote><div>…<br><blockquote style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex" class="gmail_quote">
In my opinion solution with simple login link/button (here &#39;client1&#39;) 
would be the best (standard way to handle it), we even try to convince 
client to it but unfortunately without success.<br></blockquote><br>You still haven&#39;t explained the business case surrounding the requirement, other than saying that your client wants it. <i>Why</i> do they want it? What do they hope will be accomplished by this requirement? Perhaps if you can get more details from them regarding their desires/concerns you will be better able to guide them to a solution.<br>
<br></div><div>Is it because they care about the URL? Is it because they care about the design? Is it because they want have a custom authentication they want to use instead?<br></div><div><br><blockquote style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex" class="gmail_quote">
host SSO login page on different than IdP domain only to provide user 
credentials and send this data to IdP authentication engine (to store 
session cookie)<br></blockquote><br></div><div>It&#39;s certainly possible to handle SSO outside of the IdP (as Peter mentioned), but I agree with others that it seems odd that have the login page in one location and then try to send credentials to the IdP. This is why I&#39;m trying to better understand what the rationale is.<br>
<br></div><div>Regards,<br></div><div>Ian<br></div></div></div></div></div>