(SP1-->IdP1 (simple profile)) -->SP2-->IdP2(resolve artifact profile).

David Tildesley davotnz at yahoo.co.nz
Sun Mar 8 18:50:53 EDT 2015


Hi,
I need to broker a 3rd party IdP(IdP2) which uses SAMLv2 browser profile with artifact resolution step and provides a web UI for login.
In this brokerage I would be the SAMLv2 (simple browser profile) IdP (IdP1) to my service provider partner (SP1) and be reliant on the login web UI that the 3rd party (IdP2) presents for authenticating users.
The goals:- provide a common simple browser profile identity federation with the external Service Provider.- keep the two circles of trust separate and exchange "userid" at the broker (not expose the userid from IdP2 to the SP1 but generate a pseudo ID instead and look it up from persisted source e.g. ldap directory).

Is this achievable with "back to back" connection of Shibboleth Identity and Service Provider instances?
Any advice would appreciated. I could provide a high level sequence diagram if required.
Cheers,David. 

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20150308/71994d7f/attachment-0001.html 


More information about the users mailing list