Previous Topic: Enhanced Client or Proxy Profile (ECP)

Next Topic: IDP Discovery Configuration at the Identity Provider

IDP Discovery Profile

The Identity Provider Discovery Profile provides a common discovery service that enables a Service Provider to select a unique IdP for authentication. A prior business agreement between partners is established so that all sites in the network interact with the Identity Provider Discovery service.

This profile is useful in federated networks that have more than one partner providing assertions. It enables a Service Provider to determine which Identity Provider it should send authentication requests for a particular user.

The IdP Discovery profile is implemented using a cookie domain that is common to the two federated partners. A cookie in the agreed upon domain contains the list of IdPs that the user has visited.


Copyright © 2010 CA. All rights reserved. Email CA about this topic