<div dir="ltr">Hi Peter,<div><br></div><div>Thanks for your help.  I&#39;m just trying to piece it all together as this one of the more bare topics I&#39;ve encountered on the internet.  I&#39;ll set up my own domain controller and ADFS in a lab and see if I can get it working before bugging the guys who run the corporate installation :)</div>
<div><br></div><div>Cheers,</div><div>   -Greg</div></div><div class="gmail_extra"><br><br><div class="gmail_quote">On Fri, Jun 13, 2014 at 2:00 PM, Peter Schober <span dir="ltr">&lt;<a href="mailto:peter.schober@univie.ac.at" target="_blank">peter.schober@univie.ac.at</a>&gt;</span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">* Greg Zapp &lt;<a href="mailto:greg.zapp@gmail.com">greg.zapp@gmail.com</a>&gt; [2014-06-13 02:35]:<br>
<div class="">&gt; Hmmm, right I see.  I was under the impression, somehow, that the cookie<br>
&gt; contained some verifiable information from the idP/SP required to setup the<br>
&gt; session.  Is there no way to accomplish this without a shared SP or session<br>
&gt; storage?<br>
<br>
</div>Not without bouncing the browser to the IDP.<br>
<div class=""><br>
&gt; I would think that if the second, physically separate, SP sends me<br>
&gt; back to the idP it would be able to see that I was already<br>
&gt; authenticated and just send me back with an assertion to the second<br>
&gt; ACS URL without prompting for credentials.<br>
<br>
</div>Sure, that&#39;s what I tried to hint at before:<br>
<div class="im HOEnZb"><br>
&gt; Due to SSO the user agent has with the SAML IDP this should not<br>
&gt; cause too much effort for subjects, though.<br>
<br>
</div><div class="HOEnZb"><div class="h5">-peter<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br></div>