SAML IdP Proxy

Eric Goodman Eric.Goodman at ucop.edu
Tue Mar 12 19:37:35 EDT 2013


>> Can you share any examples of where the SAML IdP proxy is implemented in the real world?

>Sure, there are EU federations based on the so-called "hub-and-spoke"
>model that employ the equivalent of a SAML IdP Proxy, I think.

We're looking at implementing this in a case where multiple cloud-hosted vendors (each of which supports SAML assertions, but their discovery services are lacking) are each trying to integrate with a defined (i.e., fixed membership) federation of IdPs. Basically, the IdP Proxy is being used on the IdP side to allow each vendor to see one IdP and "outsource" and share the DS function, and on the SP side to allow the "home" IdPs to see the multiple vendors as a single SP. (There are some other perceived benefits as well, but those are some of the main drivers).

In this case the IdP Proxy is only interacting with IdPs from within one University system, so the privacy issues are (at least arguably) less of an issue in this case.

Note that we are not using Shibboleth to perform the IdP Proxy function, but all of the IdPs being proxied are running Shibboleth.

We're also having a somewhat lively debate about whether this is the best solution in this case in particular and whether it would make sense to apply it in others.

--- Eric


More information about the users mailing list