Solved

SSO between CF & ASP.Net

Posted on 2010-09-24
5
832 Views
Last Modified: 2013-12-24
I am trying to implement a single sign on between a coldfusion site and asp.net site. The authentication part is done so that the user has to sign in only once across the 2 sites but I am having difficulty trying to manage the timeouts between the 2 sites. When the asp.net site is active I want the CF site also to be active . .and when the cold fusion site timeouts the asp.net site also has to timeout.  Is there any way to achieve this without resorting to third party software?
0
Comment
Question by:Cashmgmt
  • 3
  • 2
5 Comments
 
LVL 14

Expert Comment

by:Scott Bennett
ID: 33754654
Are these sites on the same domain name or the same server? if they are on separate servers, do they servers have a common database they share?
0
 

Author Comment

by:Cashmgmt
ID: 33757962
They are on different servers. But They share a common database.
0
 
LVL 14

Accepted Solution

by:
Scott Bennett earned 500 total points
ID: 33758097
I imagine that during your single sign on process there would be some sort of authentication token, that perhaps get saved in a cookie, or at least included with each?

I would maintain state by setting up a table in a shared database that tracks the last page view for their sessions (based on their authentication token or whatever you are passing between the sites to set up the session) regardless of what site they are on. And it would also hold whatever session information you need to make sure you can maintain the individual session on the different servers. then on both sides they would check to see when the last page view was and either time them out or log them in based on the situation and whatever time restrictions you have on the sessions.

the concept is in essence the same as using Coldfusion Client variable scope with a database for the client variable storage in a load balanced/multiple CF server environment (in fact if you had the time and inclination to build an an asp object that could interact with the cf client variable database storage that would be a really cool way to do it)
0
 
LVL 14

Expert Comment

by:Scott Bennett
ID: 33758106
first sentance should end with "or at least included with each transfer between the servers?"
0
 

Author Closing Comment

by:Cashmgmt
ID: 33769435
The solution solved the SSO problem.
0

Featured Post

Ransomware-A Revenue Bonanza for Service Providers

Ransomware – malware that gets on your customers’ computers, encrypts their data, and extorts a hefty ransom for the decryption keys – is a surging new threat.  The purpose of this eBook is to educate the reader about ransomware attacks.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A web service (http://en.wikipedia.org/wiki/Web_service) is a software related technology that facilitates machine-to-machine interaction over a network. This article helps beginners in creating and consuming a web service using the ColdFusion Ma…
If you don't have the right permissions set for your WordPress location in IIS, you won't be able to perform automatic updates. Here's how to fix the problem.
Nobody understands Phishing better than an anti-spam company. That’s why we are providing Phishing Awareness Training to our customers. According to a report by Verizon, only 3% of targeted users report malicious emails to management. With compan…

860 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question