IdP proxy with shibboleth
Cantor, Scott
cantor.2 at osu.edu
Mon Oct 13 19:33:57 EDT 2014
On 10/13/14, 6:43 PM, "Nate Klingenstein" <ndk at internet2.edu> wrote:
>
>I think the feasability will depend on which features of SAML 2.0 you're
>trying to utilize and how. Most of the best ideas in SAML 1.1 translate
>directly into SAML 2.0, but not necessarily the other way around.
>Basically, set up a service provider that protects the authentication
>endpoint of your identity provider.
>
>I don't think Shibboleth is used for proxying between protocols often,
>though. simpleSAMLphp is more used in my experience.
When the reasons are legitimate and not the usual whining about Java or
Apache, the main reason is that the IdP doesn't include a data connector
for attribute resolution that pulls data from the request attributes set
by Apache. I forgot to get a task defined for that for V3, but I should be
able to knock it out before we ship.
-- Scott
More information about the users
mailing list