SAML IdP Proxy

Cantor, Scott cantor.2 at osu.edu
Wed Mar 13 10:14:08 EDT 2013


On 3/13/13 9:47 AM, "Mark Scheible" <mscheible at mailbox.mcnc.org> wrote:

>I don't see a problem with this scenario.  The institutional IdPs would
>be sending their assertions through the SP side of the proxy, but they
>would be responding to the individual vendor SPs, and the assertions
>should contain the attributes requested by each vendor SP.

That's virtually never how it works in practice. Most gateways are opaque
by design and don't expose enough information for the IdP to do anything
but send it the superset.

Of course that may not apply to any particular gateway or this one, it's
just the most common case.

-- Scott




More information about the users mailing list