Shibboleth IDP trust with other IDP

Cantor, Scott cantor.2 at osu.edu
Mon Mar 3 22:53:20 EST 2014


On 3/3/14, 10:31 PM, "krrishv" <krish.v at gmail.com> wrote:

>Because we want to create a portal with this secondary IDP which hosts
>couple
>of applications and we want to access 2nd IDP applications also in this
>portal. It is like we want one stop place. If we can build a trust between
>this two IDP then i think we can access the stuffs. That is what i was
>thinking.

An IdP is not a portal, and certainly this IdP implementation isn't.

Regardless, I've told you the answer. If you want to stick an extra IdP
you don't need in between the real IdP and the applications, that's a
proxy IdP, and the earlier thread is about exactly the issues with doing
that if the proxy is done with the Shibboleth IdP. You need an SP in front
of that IdP to broker the SAML between the real IdP and the proxy.

-- Scott




More information about the users mailing list