<div dir="ltr"><div class="gmail_default" style="font-family:"trebuchet ms",sans-serif">Hi Scott,</div><div class="gmail_default" style="font-family:"trebuchet ms",sans-serif"><br></div><div class="gmail_default" style="font-family:"trebuchet ms",sans-serif">Your comments have answered most of my queries. Thank you so much.</div><div class="gmail_default" style="font-family:"trebuchet ms",sans-serif"><br></div><div class="gmail_default" style="font-family:"trebuchet ms",sans-serif"><span style="font-family:arial,sans-serif;font-size:12.8px">> All the applications (not shibboleth SP's but support SAML) trying to achieve</span><br style="font-family:arial,sans-serif;font-size:12.8px"><span style="font-family:arial,sans-serif;font-size:12.8px">> SSO using Shibboleth IDP( based on SAML) should have only common login</span><br style="font-family:arial,sans-serif;font-size:12.8px"><span style="font-family:arial,sans-serif;font-size:12.8px">> parameters like username and password for authentication?</span><br></div><div class="gmail_default" style="font-family:"trebuchet ms",sans-serif"><br></div><div class="gmail_default" style="font-family:"trebuchet ms",sans-serif">Sorry I was not clear before. By "parameters", I meant that if I were to use IDP login page, then only username and password would be given for authentication. For any additional input login parameters, relaytoken will be used. Please confirm.</div><div class="gmail_default" style="font-family:"trebuchet ms",sans-serif"><br></div><div class="gmail_default" style="font-family:"trebuchet ms",sans-serif"><br></div><div class="gmail_default" style="font-family:"trebuchet ms",sans-serif">Regards,</div><div class="gmail_default" style="font-family:"trebuchet ms",sans-serif">Virajitha</div><div class="gmail_default" style="font-family:"trebuchet ms",sans-serif"><br></div><div class="gmail_default" style="font-family:"trebuchet ms",sans-serif"><br></div></div><div class="gmail_extra"><br><div class="gmail_quote">On Tue, Nov 1, 2016 at 6:56 AM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">> All the applications (not shibboleth SP's but support SAML) trying to achieve<br>
> SSO using Shibboleth IDP( based on SAML) should have only common login<br>
> parameters like username and password for authentication?<br>
<br>
The applications have *no* parameters for authentication. They have nothing to do with the process. They issue a SAML request. That's it. That does not include a name or a password.<br>
<br>
> The reason I amĀ  asking this is, my web application requires additional parameter say a<br>
> "location" for login.<br>
<br>
Anything your application needs to recover afterwards has to be saved off and bound to a RelayState token. You send the RelayState parameter along with the SAML request and the IdP will return it in the form response back.<br>
<br>
If you want to use SAML you need to deploy an existing SAML SP package, Shibboleth or otherwise. It handles all these issues for you.<br>
<span class="HOEnZb"><font color="#888888"><br>
-- Scott<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br>
</font></span></blockquote></div><br><br clear="all"><div><br></div>-- <br><div class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><br></div><div>Regards,</div><div>Virajitha</div></div></div>
</div>