Page tree

The Shibboleth 2.x software has reached its End of Life and is no longer supported. This documentation is available for historical purposes only. See the IDP4 and SP3 wiki spaces for current documentation on the supported versions.

Skip to end of metadata
Go to start of metadata

SP-Initiated SSO

When configuring Shibboleth SP to use a PingFederate (PingIdentity) IdP, do not use the "/idp/" endpoint as this is a proprietary Ping endpoint for IdP-Initiated SSO which is not for SAML 2 requests and will drop the RelayState parameter.  Use the "/idp/SSO.saml2" endpoint for expected Shibboleth SP behavior.

PingFederate has non-standard metadata handling and usage and is unable to automatically consume multiple entity descriptions at once.

  • No labels