【问题标题】:Shibboleth SP to point to multiple idPShibboleth SP 指向多个 idP
【发布时间】:2014-02-18 15:23:01
【问题描述】:

我在一台机器上安装了 SP。 我需要根据 url 将其配置为多个 idP。

例如。 我们有两个主机 one.myorg.comtwo.myorg.com 都指向同一个模块/机器 - 所以同一个 SP。

现在我需要将我的 sp 配置为好像one.myorg.com/secure 被命中 SP 应该转到 https://testshib.com/idp 进行身份验证,否则 two.myorg.com/secure 被命中 SP 应该转到 https://myown.idp.com idp。

编辑:它不应该要求选择 idP。

【问题讨论】:

    标签: single-sign-on shibboleth opensaml


    【解决方案1】:

    如果这仍然是真实的,您可以在 这里找到一些提示:https://wiki.shibboleth.net/confluence/display/SHIB2/IdPDiscovery. 在 Shibboleth Wiki here

    关键思想是在手动制作的对 SP 登录模块的登录请求中向相关 IdP 提供 entityID,例如

    https://sp.testshib.org/Shibboleth.sso/TestShib?entityID=https%3A%2F%2Fidp.testshib.org%2Fidp%2Fshibboleth
    

    其中entityID=... 是相关 IdP 的 url 编码 entityID。

    此参数的文档可以在“高级配置”部分中找到on the Shibboleth Wiki

    【讨论】:

    猜你喜欢
    • 2017-06-09
    • 1970-01-01
    • 2016-09-16
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 2013-05-11
    相关资源
    最近更新 更多