SAML IdP Proxy

Cantor, Scott cantor.2 at osu.edu
Wed Mar 13 11:16:12 EDT 2013


On 3/13/13 10:32 AM, "Ortner Nikolaus" <N.Ortner at fh-kaernten.at> wrote:

>> I don't see a problem with this scenario.
>
>Well, I could imagine:
>* performance-issues, latency
>* installing a single point of failure
>
>Maybe building a separate federation of the cross-federated SPs and IdPs
>could be an option?
>If the scenario results in full interop of the 2 federations -> why not
>merge them?
>
>But I am quite sure that I've missed some important points.

Well, and I say this because we have a vendor with the same problem, the
salient factor here is that the SP(s) in question are actually unable to
support multiple IdPs for a single customer. This fairly common because of
the anti-pattern of "issuer = customer".

We have a local problem (it's a people issue, not a technical one) with
getting dependents into our IDM system, and so we had an app that needed
to handle both our IdP and a separate source of accounts for dependents.
The solution was in fact the same one, a gateway to combine them into one
IdP from the point of view of the SP.

Broken apps and bad decision making trump a lot of other aspects.

-- Scott




More information about the users mailing list