IdP proxy with shibboleth
Nate Klingenstein
ndk at internet2.edu
Mon Oct 13 18:43:42 EDT 2014
Matthieu,
I think the feasability will depend on which features of SAML 2.0 you're trying to utilize and how. Most of the best ideas in SAML 1.1 translate directly into SAML 2.0, but not necessarily the other way around. Basically, set up a service provider that protects the authentication endpoint of your identity provider.
I don't think Shibboleth is used for proxying between protocols often, though. simpleSAMLphp is more used in my experience.
Hope this helps,
Nate.
On Oct 13, 2014, at 4:08 PM, Matthieu Huin <matthieu.huin at enovance.com> wrote:
> Hello,
>
> I'm looking into the feasability of setting up an IdP proxy between a SAML2 SP and a SAML1.1 IdP. All I could find in terms of documentation or previous experience is this: https://spaces.internet2.edu/display/GS/SAMLIdPProxy and this documentation for OpenAM: https://wikis.forgerock.org/confluence/display/openam/SAMLv2+IDP+Proxy+Part+1.+Setting+up+a+simple+Proxy+scenario
>
> I'd be grateful if anyone could share experiences or documentation on the subject.
>
> Matthieu Huin
>
> mhu at enovance.com
> http://www.enovance.com
> 11 bis rue roquépine – 75008 PARIS France
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list