Shib/SAML Clarification

Joshua Riffle jriffle at apu.edu
Mon Jul 23 13:30:09 EDT 2012


Hi,
  I have been following the conversation regarding using a reverse proxy in
front of a Shibboleth IDP and I'm probing some possible workarounds. One of
them includes modifying my IDP's metadata to report the internal host name
rather than the front-facing proxy's host name. My intuition tells me this
would not work but I can't find any documentation to support it one way the
other.

if idpfrontproxy.example.edu is changed to idpbackend.example.edu in my
SAML EndPoints would it work or does the SP use the Location URL in IDP's
metadata to determine what URL to use?

<AttributeService
Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="
https://idpfrontproxy.example.edu/profile/SAML1/SOAP/AttributeQuery"/>

Secondly, has anyone tried using the ResponseLocation optional field to use
a communicating URL that differs from the EndPoint Location?

Joshua Riffle
Software Engineer
*Azusa Pacific University*
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20120723/75724b3f/attachment.html 


More information about the users mailing list