<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style type="text/css" style="display:none"><!--P{margin-top:0;margin-bottom:0;} @font-face
        {font-family:Calibri}
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif"}
a:link, span.MsoHyperlink
        {color:blue;
        text-decoration:underline}
a:visited, span.MsoHyperlinkFollowed
        {color:purple;
        text-decoration:underline}
span.EmailStyle17
        {font-family:"Calibri","sans-serif";
        color:windowtext}
.MsoChpDefault
        {font-family:"Calibri","sans-serif"}
@page WordSection1
        {margin:1.0in 1.0in 1.0in 1.0in}--></style>
</head>
<body dir="ltr">
<div id="divtagdefaultwrapper" style="font-size:12pt;color:#000000;background-color:#FFFFFF;font-family:Calibri,Arial,Helvetica,sans-serif;">
<p>Shibboleth is an implementation of SAML. So if you understand how SAML works, you understand what Shibboleth is doing. Start here for basic SAML description:<br>
</p>
<p><br>
</p>
<p><a id="lnk399212" href="http://en.wikipedia.org/wiki/Security_Assertion_Markup_Language">http://en.wikipedia.org/wiki/Security_Assertion_Markup_Language</a></p>
<p><br>
</p>
<p><a id="lnk573904" href="https://blog.surfnet.nl/?p=1417">https://blog.surfnet.nl/?p=1417</a></p>
<p><br>
</p>
<p><br>
</p>
<p><br>
</p>
<div style="color: rgb(33, 33, 33);">
<hr tabindex="-1" style="display:inline-block; width:98%">
<div id="divRplyFwdMsg" dir="ltr"><font style="font-size:11pt" face="Calibri, sans-serif" color="#000000"><b>From:</b> users-bounces@shibboleth.net <users-bounces@shibboleth.net> on behalf of Sathish Anickode <SAnickode@skytouchtechnology.com><br>
<b>Sent:</b> Wednesday, December 17, 2014 9:02 PM<br>
<b>To:</b> Shib Users<br>
<b>Subject:</b> Shibboleth Authentication request flow</font>
<div> </div>
</div>
<div>
<div class="WordSection1">
<p class="MsoNormal">I would like to understand how the authentication request flows between the user’s browser, SP and IdP.</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal">A user accesses a resource on a SP for the first time and since there is no associated authenticated session, a SAML request is sent to the IdP to authenticate the user. Since the user does not have an associated session on the IdP, does
the IdP send back a SAML response requesting the user to be redirected to the login page? Can you please clarify how this interaction works?</p>
<p class="MsoNormal"> </p>
<p class="MsoNormal"></p>
</div>
</div>
</div>
</div>
</body>
</html>