SAML IdP Proxy
Andrew Owen
andrew at search.org
Mon Mar 11 08:33:51 EDT 2013
Thank you Pete, I'll look at this. The ideal solution for my situation would be similar to the IdP proxy concept where members across federations don't have to be aware of each other's metadata, instead the "IdP Proxy" serves as a broker of sorts that enables cross-federation communication.
Thanks,
-Andrew
916.215.3933
-----Original Message-----
From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] On Behalf Of Peter Schober
Sent: Monday, March 11, 2013 8:04 AM
To: users at shibboleth.net
Subject: Re: SAML IdP Proxy
* Andrew Owen <andrew at search.org> [2013-03-11 12:54]:
> We have a requirement for cross-federation interoperability (allow
> IdPs in one federation to authenticate its users to access SPs in
> another federation), after some poking around I stumbled across this
> link which introduces the concept of a SAML IdP Proxy:
You could also deal with interfederation itself and make sure metadata from each federation is available to members of the other.
E.g. via https://wiki.shibboleth.net/confluence/display/MA1
-peter
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list