OAM - OIF 11.1.2.3: Session behaviour between webgates and federated partnerships
Hi, we're currently developing a SSO solution for a customer and a question just arose and this is the scenario:
* We have two applications that must be protected/authenticated by OAM (APPWG and APPFD)
* APPWG uses a webgate to protect resources (installed on IIS 7.x) and APPFD is a trusted Service Provider in a federation relationship with OAM.
* What happens when a user logs in to APPWG and APPWG re-directs him to APPFD? Is there a re-authentication process? Does the session survive to this interaction? I understand that the session could live since it's the same HTTP session and it has some OAM cookies on it as well, but this is just a hunch and we need to give an accurate answer on this topic.