IdP proxy with shibboleth

Tom Scavo trscavo at gmail.com
Mon Oct 13 18:45:02 EDT 2014


On Mon, Oct 13, 2014 at 6:08 PM, Matthieu Huin
<matthieu.huin at enovance.com> wrote:
>
> I'm looking into the feasability of setting up an IdP proxy between a SAML2 SP and a SAML1.1 IdP. All I could find in terms of documentation or previous experience is this: https://spaces.internet2.edu/display/GS/SAMLIdPProxy

I wrote that wiki page way back when but it was J.P. Robinson at UAB
who first configured Shibboleth as an IdP Proxy almost 10 years ago, I
believe. It can be done but better tools have appeared in the
meantime. I'm talking about simpleSAMLphp of course, which is
preferred for this type of deployment. All the hub-and-spoke
federations of the EU are based on simpleSAMLphp, AFAIK.

> I'd be grateful if anyone could share experiences or documentation on the subject.

We have two such deployments in production today, an OpenID
Connect-to-SAML gateway and a SAML-to-SAML IdP Proxy, both based on
simpleSAMLphp, and both provided by Cirrus Identity. Maybe they have
some documentation on their web site, (http://cirrusidentity.com/) I
don't know.

Hope this helps,

Tom


More information about the users mailing list