OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

saml-dev message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Re: [saml-dev] I have created a sample SSO scenario; Am I understanding correctly how SAML is to be used?


On 5/9/06, Cahill, Conor P <conor.p.cahill@intel.com> wrote:
>
> > Is there something I'm missing here?  Is there some reason
> > why the SP must initiate the request?  If not, this is a
> > piece of cake. :-)
>
> The main reason why people generally don't like the IdP-first
> model (which, as you said does work) is that it means that
> bookmarks or any form of direct access to the SP won't work.

An SP can support both profiles (SP-first and IdP-first)
simultaneously.  An IdP-first flow doesn't require IdP discovery, so
use it whenever possible.  If a user requests a resource at the SP, on
the other hand, additional steps are required, including possible
interactions with the user.  All I'm saying is, if this can be
avoided, why not do so?

Tom


[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]