Single Sign on using Shibboleth

戏子无情 提交于 2019-12-06 04:32:19

In order to accomplish what you'd like, you will need to SAML-enable not only abc.com but all the third party applications as well. Basic SAML Web SSO works under the assumption that each protected service communicates with the IdP.

So, if all parties support SAML Web SSO you'll end up with something like this:

  1. User goes abc.com, gets redirect to their IdP, logs in to start a new session, gets redirected back to abc.com and is allowed in
  2. User clicks on link, presented by abc.com, to Application A
  3. User goes to Application A, gets redirected to IdP, is not prompted to log in since a session exists, gets redirected by Application A and is allowed.

Rinse and repeat step 3 for each third party application.

In addition to what Chad said, you need to setup your shibboleth configuration file correctly for each application. (Mine is called shibboleth2.xml.) That configures your .NET application (I assume running under IIS with a certificate) to securely pass the logon values to the IdP for auth. IIS should have the HTTP redirect set to MATCH the shibboleth configuration, probably https://abc.com/secure in your case.

易学教程内所有资源均来自网络或用户发布的内容,如有违反法律规定的内容欢迎反馈
该文章没有解决你所遇到的问题?点击提问,说说你的问题,让更多的人一起探讨吧!