Shib/SAML Clarification

Cantor, Scott cantor.2 at osu.edu
Mon Jul 23 13:34:35 EDT 2012


On 7/23/12 1:30 PM, "Joshua Riffle" <jriffle at apu.edu> wrote:
>
>  I have been following the conversation regarding using a reverse proxy
>in front of a Shibboleth IDP and I'm probing some possible workarounds.
>One of them includes modifying my IDP's metadata to report the internal
>host name rather than the front-facing
> proxy's host name. My intuition tells me this would not work but I can't
>find any documentation to support it one way the other.

It won't work.

>if idpfrontproxy.example.edu <http://idpfrontproxy.example.edu> is
>changed to
>idpbackend.example.edu <http://idpbackend.example.edu> in my SAML
>EndPoints would it work
> or does the SP use the Location URL in IDP's metadata to determine what
>URL to use?

What else could it use?

>Secondly, has anyone tried using the
>ResponseLocation optional field to use a communicating URL that differs
>from the EndPoint Location?

Not really, but that's for splitting request and response endpoints for a
given profile, and that doesn't help you any.

-- Scott



More information about the users mailing list