IdP proxy with shibboleth

Cantor, Scott cantor.2 at osu.edu
Mon Oct 13 19:33:57 EDT 2014


On 10/13/14, 6:43 PM, "Nate Klingenstein" <ndk at internet2.edu> wrote:
>
>I think the feasability will depend on which features of SAML 2.0 you're
>trying to utilize and how.  Most of the best ideas in SAML 1.1 translate
>directly into SAML 2.0, but not necessarily the other way around.
>Basically, set up a service provider that protects the authentication
>endpoint of your identity provider.
>
>I don't think Shibboleth is used for proxying between protocols often,
>though.  simpleSAMLphp is more used in my experience.

When the reasons are legitimate and not the usual whining about Java or
Apache, the main reason is that the IdP doesn't include a data connector
for attribute resolution that pulls data from the request attributes set
by Apache. I forgot to get a task defined for that for V3, but I should be
able to knock it out before we ship.

-- Scott



More information about the users mailing list