On 27/01/2014 17:50, "Peter Schober" <
peter....@univie.ac.at> wrote:
>* Andy Creed <
an...@provun.com> [2014-01-27 18:10]:
>> Ah I see what you mean. So that leads to the next question. If the user
>>is
>> authenticated via SSO from A does that mean they are authenticated at B
>>as
>> well?
>
>I'm not sure what scenario (of the several discussed) you're referring
>to here, specifically.
>
>Also I find all of this of very little value to the SSP community, so
>I'll stop here.
Let me explain the scenario further to avoid any ambiguity as much as
possible.
If a user has already been authenticated from an IdP at point A and they
have visited an SP at point via IdP first would they then be authenticated
for an IdP first to point C. I appreciate that my terminology might not be
accurate but that is because you are the export from whom I am asking help.
>
>> If they are do we need to ensure that the SSO session expiry time is
>> large to allow them to visit B and not expire before they choose to
>> visit C?
>There's nothing in the SAML standard or SimpleSAMLphp that will make
>sure a session at an IDP will only expire after the subject has
>accessed a certain SP.
>
>Also, does that mean we're now back to using IDP A for users of SP C,
>even though you said that cannot happen?
I am not sure to be honest as I feel whatever I try an explain is falling
short of enough information for you.
>
>> Also, how do we insert other attributes into the SAML response from
>> B when the user clicks on the IdP first URL?
>
>IdP-first or not (i.e., SP-initiated) is immaterial for what
>attributes get release. Just like IdP-first or not is immaterial for
>how the IDP will authenticate the subject.
>I don't know why people keep obsessing about IDP-first. (Probably
>because they're mistaken in thinking IdP-first will give them some
>shortcut or something, when it's just a crippled replacement for
>proper initiation by the SP, with more effort for everyone involved,
and a worse UX).
OK. So whether they are IdP first or SP initiated how do attributes get
set within a SAML response via SSP? Does that make sense?
Thank you for your help so far although I get the feeling you are losing
patience with my questions.