<div dir="ltr"><div><div class="gmail_signature"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div><div><font face="monospace, monospace">Hi ,</font></div></div><div><font face="monospace, monospace">Following is the scenario :<br></font></div><div><font face="monospace, monospace">I have 2 sp's configured for 1 application say sp1 and sp2 both are protected by single idp .We have added support for two authentication methods simultaneously 1.Password authentication</font></div><div><font face="monospace, monospace">2.External authentication .</font></div><div><font face="monospace, monospace"><br></font></div><div><font face="monospace, monospace">Flow :</font></div><div><font face="monospace, monospace">1.User hits application via sp1 ,user asked for authentication and idp session is created.(using External authentication)</font></div><div><font face="monospace, monospace">2.User next hits the application via sp2 and is redirected to idp login page .(Password authentication)</font></div><div><font face="monospace, monospace"><br></font></div><div><font face="monospace, monospace">Though idp session existsin step 2 user is asked for authentication.It should take the existing session created in step 1 at the time of external authentication.</font></div><div><font face="monospace, monospace"><br></font></div><div><font face="monospace, monospace">So could you please tell me hows shibboleth verifies the existing session which makes SSO work .</font></div><div><br></div></div></div></div></div></div></div>
</div>