<html>
  <head>
    <meta content="text/html; charset=windows-1252"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <br>
    <div class="moz-cite-prefix">On 12/23/14 7:07 PM, Cantor, Scott
      wrote:<br>
    </div>
    <blockquote cite="mid:95B4965D-067D-4630-A5E8-C3409FA72F58@osu.edu"
      type="cite">
      <pre wrap="">
</pre>
      <blockquote type="cite">
        <pre wrap="">Apparently deep linking only works using IdP initiated SSO in Ping's
implementation 
(<a class="moz-txt-link-freetext" href="http://documentation.pingidentity.com/display/SFC/SP-Initiated+SSO+via+De">http://documentation.pingidentity.com/display/SFC/SP-Initiated+SSO+via+De</a>
ep+Linking).
</pre>
      </blockquote>
      <pre wrap="">
Which is not IdP-initiated SSO, QED.</pre>
    </blockquote>
    The title is misleading.  If you read the Note part it says:<br>
    <meta charset="utf-8">
    <span style="color: rgb(60, 60, 60); font-family: 'Helvetica Neue',
      Helvetica, Arial, sans-serif; font-size: 13px; font-style: normal;
      font-variant: normal; font-weight: normal; letter-spacing: normal;
      line-height: 17.3333339691162px; orphans: auto; text-align: left;
      text-indent: 0px; text-transform: none; white-space: normal;
      widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px;
      display: inline !important; float: none; background-color:
      rgb(250, 249, 249);">"For deep linking to work, IdP-initiated SSO
      via the Authentication Service must have been performed previously
      for that user. Salesforce redirects the user only when it finds
      the ssostartpage cookie, which is set only during IdP-initiated
      SSO via the Authentication Service."</span>
    <blockquote cite="mid:95B4965D-067D-4630-A5E8-C3409FA72F58@osu.edu"
      type="cite">
      <blockquote type="cite">
        <pre wrap="">
We can argue how clumsy it is, but it's possible.
</pre>
      </blockquote>
      <pre wrap="">
It is not. Literally, it is physically impossible to do. Anything you 
think is IdP-initiated that is using a deep link (that is, starting at the 
SP end) is an SP-initiated flow with a proprietary message, and is thus 
not a standard use of SAML.</pre>
    </blockquote>
    Agree that this has to be a proprietary solution of some kind, until
    some company like Ping with deep pocket push it through OASIS.<br>
    <blockquote cite="mid:95B4965D-067D-4630-A5E8-C3409FA72F58@osu.edu"
      type="cite">
      <pre wrap="">

</pre>
      <blockquote type="cite">
        <pre wrap="">To many legacy enterprise applications, IdP initiated SSO may be the only 
SSO option,
not just to Salesforce.
</pre>
      </blockquote>
      <pre wrap="">
That doesn't make them any less buggy, and it doesn't make IdP-initiated a 
good choice, which is what the OP asked. I didn't give him the full answer 
to that question, but I think this thread did.

-- Scott

</pre>
    </blockquote>
    The reason I stayed long on this thread and loved seeing so many
    responses is because we do have a big client who actually wants
    IdP-initiated SSO/Login to be implemented.  So regardless of the
    pros/cons, how well can Shibboleth handle IdP-initiated SSO?   Has
    anyone used this feature in a Shib-based IdP implementation? <br>
    <br>
    Thanks!<br>
    <br>
    Nick<br>
    <br>
  </body>
</html>