<div dir="ltr">Hi!<div><br></div><div>Client is forcing this solution because don&#39;t want to change current user experience. In current site there are two places which user could use to log in (top bar/separate page) and after we create our portal - user experience should not change he should still log in using the same (currently existing) components.</div>
<div>if there will be only single place to log in (in current solution) - separate page, then we&#39;ll be able to prepare page which will look similar at IdP, but the problem is with top bar login which is on all public pages - we are not able to &quot;simulate&quot; this on IdP side.</div>
<div><br></div><div>Best Regards</div><div>Pawel</div></div><div class="gmail_extra"><br><br><div class="gmail_quote">2014-05-07 16:05 GMT+02:00 Ian Rifkin <span dir="ltr">&lt;<a href="mailto:irifkin@brandeis.edu" target="_blank">irifkin@brandeis.edu</a>&gt;</span>:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr">Hi,<br><br><div><div class="gmail_extra"><div class="gmail_quote"><div class=""><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
<div dir="ltr"><div class="gmail_extra">
Client requirement is that login forms should be part of client1/2 sites not IdP domain (only should communicate with IdP to handle authentication).</div></div></blockquote></div><div>…<div class=""><br><blockquote style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex" class="gmail_quote">

In my opinion solution with simple login link/button (here &#39;client1&#39;) 
would be the best (standard way to handle it), we even try to convince 
client to it but unfortunately without success.<br></blockquote><br></div>You still haven&#39;t explained the business case surrounding the requirement, other than saying that your client wants it. <i>Why</i> do they want it? What do they hope will be accomplished by this requirement? Perhaps if you can get more details from them regarding their desires/concerns you will be better able to guide them to a solution.<br>

<br></div><div>Is it because they care about the URL? Is it because they care about the design? Is it because they want have a custom authentication they want to use instead?<br></div><div class=""><div><br><blockquote style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex" class="gmail_quote">

host SSO login page on different than IdP domain only to provide user 
credentials and send this data to IdP authentication engine (to store 
session cookie)<br></blockquote><br></div></div><div>It&#39;s certainly possible to handle SSO outside of the IdP (as Peter mentioned), but I agree with others that it seems odd that have the login page in one location and then try to send credentials to the IdP. This is why I&#39;m trying to better understand what the rationale is.<br>

<br></div><div>Regards,<br></div><div>Ian<br></div></div></div></div></div>
<br>--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br></blockquote></div><br></div>