SAML single-signon — implementation experience

I've recently had the pleasure of figuring out how to set up SAML-based single signon. This was for a SaaS offering (at Glance Networks, my employer).  Here are some of the things I learned along the way. I set up a so-called SAML Service Provider: a service that gets information about user identities from Identity