SAML IdP Proxy

Tom Scavo trscavo at gmail.com
Mon Mar 11 09:09:21 EDT 2013


On Mon, Mar 11, 2013 at 7:54 AM, Andrew Owen <andrew at search.org> wrote:
>
> We have a requirement for cross-federation interoperability (allow IdPs in one federation to authenticate its users to access SPs in another federation), after some poking around I stumbled across this link which introduces the concept of a SAML IdP Proxy: https://spaces.internet2.edu/display/GS/SAMLIdPProxy

Oh, I was looking for that over the weekend but couldn't find it. Thanks! :-)

> This sounds like a promising approach to enable cross-federation interoperability but I’d like to learn more.

Yes, I attended a meeting last week where they are considering exactly
that. However, keep in mind that metadata aggregation is an
alternative approach, with significant mindshare at the moment. AFAICT
the proxy approach and the aggregation approach are equivalent.

> Is there any documentation available about how to implement this pattern using the Shibboleth IdP and SP?

No, I don't think so. As it turns out, simpleSAMLphp is perhaps better
for this purpose.

> Can you share any examples of where the SAML IdP proxy is implemented in the real world?

Sure, there are EU federations based on the so-called "hub-and-spoke"
model that employ the equivalent of a SAML IdP Proxy, I think.

> I appreciate any additional detail you’re able to provide.

Hope this helps,

Tom


More information about the users mailing list