advocacy tips
Cantor, Scott
cantor.2 at osu.edu
Thu Dec 1 16:27:06 EST 2016
> To summarize, I think you are saying that Shibboleth IdP does not currently
> have any real support for SAML proxying right now, but it may, some day,
> since Shibboleth is committed leading the charge in SAML support.
We recognize it's an inevitable requirement of too many people to keep treating it as optional, yes. Whether we are successful in convincing our board and members that that's worth spending our resources on remains to be seen.
> What's not clear to me, however, is why it would be necessary to add
> support to Shibboleth SP for SAML proxying.
I didn't mean to imply we would. You may be confusing what I said about the way you'd proxy with the IdP today, which is to stick an SP in front of it.
> I would have expected the
> whole notion of SAML proxying to be completely opaque to any SP that is
> authenticating through an IdP that happens to be acting as a proxy for
> another IdP. I mean, why should the SP care whether the IdP authenticates
> the user on its own or by delegation?
There are applications that care about the security and privacy implications of proxying and there are some mechanisms in SAML for communicating that back through the chain and the Shibboleth SP supports extracting those details where warranted.
-- Scott
More information about the users
mailing list