<div dir="ltr">Thanks for all the explanation !!!!!<div>We don't plan to put the sp on apache httpd for the moment for 2 reasons:</div><div>- httpd runs on solaris OS and our infrastructure seems to have some trouble to built the sp plugin for it...</div><div>- Whith sp on httpd we still need to do something to create a java/.Net user session so that application could use authenticate user(with Principal in java) information.</div><div>Thanks for all the time spent to answer me.</div><div><br></div><div>   </div></div><div class="gmail_extra"><br><div class="gmail_quote">2017-03-16 21:41 GMT+01:00 Peter Schober <span dir="ltr"><<a href="mailto:peter.schober@univie.ac.at" target="_blank">peter.schober@univie.ac.at</a>></span>:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">* Peter Schober <<a href="mailto:peter.schober@univie.ac.at">peter.schober@univie.ac.at</a>> [2017-03-16 21:38]:<br>
<span class="">> > How is it possible that the idp detects that the user has already<br>
> > been indentified on it's own system ? My guess was that a cookie was<br>
> > set on the idp domain with the session id.<br>
><br>
> Yes, but what the IDP does to recognize the subject is not specified<br>
> by SAML).<br>
<br>
</span>Also, there's no need to set an HTTP Cookie "on the idp domain" (as in<br>
a cookie any host sharing a DNS domain with the IDP can read), only a<br>
cookie for the FQDN of the IDP itself suffices.<br>
The IDP is the one setting the cookie, and the IDP is the only one<br>
needing to read it back from the HTTP User Agent.<br>
<div class="HOEnZb"><div class="h5">-peter<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br>
</div></div></blockquote></div><br></div>