<div dir="ltr">Well Scott -<div><br></div><div>If the service (SP) doesn't have a facility for SP-initated SAML login, and I want to enforce SAML across my org - is there a way around providing my users with a link of some sort to click on first?</div><div><br></div><div>I'm perhaps being a bit intentionally obtuse here - but if I want my users to utilize SAML only, and the service requires unsolicited SAML - don't I *have* to provide a link of some sort to my users? Is there any other way? (now I'm being truly honest and asking).</div><div><br></div><div>Thanks!</div></div><div class="gmail_extra"><br><div class="gmail_quote">On Wed, Dec 3, 2014 at 5:23 PM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">On 12/3/14, 9:29 PM, "Jason Walton" <<a href="mailto:jwalton@outbrain.com">jwalton@outbrain.com</a>> wrote:<br>
><br>
>I'm trying to work with a service that requires IDP initiated, also<br>
>called "unsolicited" login. There appears to be a provision in Shibboleth<br>
>for this via a custom crafted URL - but is there anything beyond this?<br>
>It's unclear to me how to deploy this to users without developing my own<br>
>full-featured "App Portal" ala Okta or OneLogin.<br>
<br>
</span>I don't think "link on a page" requires an app portal, but your real<br>
problem is that your users will just bookmark or reenter the app URL and<br>
go direct. No portal fixes that.<br>
<span class=""><br>
>Can someone shed some light on this for me? Or is there another open<br>
>source project somewhere that already exists to help implement a SAML<br>
>authenticated app portal or link-list for end users?<br>
<br>
</span>I think you may be overthinking this.<br>
<span class="HOEnZb"><font color="#888888"><br>
-- Scott<br>
</font></span><div class="HOEnZb"><div class="h5"><br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br><br clear="all"><div><br></div>-- <br><div class="gmail_signature"><div dir="ltr"><div style="font-family:arial;font-size:small">Jason Walton</div><div style="font-family:arial;font-size:small">IT Security Manager</div><div style="font-family:arial;font-size:small"><a href="mailto:jwalton@outbrain.com" target="_blank">jwalton@outbrain.com</a></div></div></div>
</div>
<br>
<div><font size="1"><font face="Arial, Helvetica, sans-serif">The above terms reflect a potential business arrangement, are provided </font><font face="Arial, Helvetica, sans-serif">solely as a basis for further discussion, and are not intended to be and do </font><span style="font-family:Arial,Helvetica,sans-serif">not constitute a legally binding obligation. No legally binding obligations </span><span style="font-family:Arial,Helvetica,sans-serif">will be created, implied, or inferred until an agreement in final form is </span><span style="font-family:Arial,Helvetica,sans-serif">executed in writing by all parties involved.</span></font></div><div><font face="Arial, Helvetica, sans-serif" size="1"><br></font></div><div><font size="1"><font face="Arial, Helvetica, sans-serif">This email and any attachments hereto may be confidential or privileged. If you received this </font><span style="font-family:Arial,Helvetica,sans-serif">communication by mistake, please don't forward it to anyone else, please </span><span style="font-family:Arial,Helvetica,sans-serif">erase all copies and attachments, and please let me know that it has gone </span><span style="font-family:Arial,Helvetica,sans-serif">to the wrong person. Thanks.</span></font></div>