How to add relying party (Azure AD (AFDS)) to Shib IdP V3
Peter Schober
peter.schober at univie.ac.at
Fri Jun 8 02:29:40 EDT 2018
* Jesper <jesper.laursen at lego.com> [2018-06-07 08:02]:
> I actually also thought that I only need the SP and then make it use
> the IdP on Azure (AFDS).
Only you can know what's required for your use-case.
The SP is the resource owner.
The IDP has the identities.
Most orgs will be both, some will only be SPs.
> But all examples so far I have found indicates that the
> relying-party.xml for the IdP must be altered.
Then you're looking at the wrong examples.
The Shibboleth consortium makes implamentations for both the SP and IDP.
And MS-ADFS works in both roles simultaneously by default, IIRC.
So there's plenty of potential of confusion if you don't know what
exactly you're looking for. Certainly searching the web for generic
things like "Shibboleth" and "ADFS" will cover other cases, too.
-peter
More information about the users
mailing list