Use of embedded discovery service/Idp Proxy

Sukesh Nischal Sukesh.Nischal at itslearning.com
Thu Jun 28 16:46:48 BST 2012


Hi

I have a scenario where I have multiple ADFS servers belonging to individual schools. All the schools need to access a single web service that we provide, but by authenticating with their own ADFS server.

At first glance I thought the solution was to put in a discovery service in between our site and the numerous ADFS servers, so that the end user could select which ADFS server to authenticate with. However, it turns out that the SAML client (Service Provider) software being used on our end,  is something based on FEIDE. It is very basic, and doesn't support connecting to a discovery service. It can only connect to a single IdP using metadata only. I.e there is a web.config file in which refers to an IDP by its metadata only, I cannot use things like SessionInitiator to invoke a discovery service.

Could the embedded discovery service be adapted to help in this situation? I've also been looking at IdP proxy but cant understand if this will also let an end user choose their authentication point? Any tips would be appreciated!


Sukesh Nischal

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20120628/75d326c2/attachment.html 


More information about the users mailing list