Post saml reponse from one shib idp to other shib idp

David Huebner david.huebner at daasi.de
Wed May 16 09:36:32 EDT 2018


On 15.05.2018 18:11, Peter Schober wrote:
>> So My requirement is that" if user enter this email then user should
>> authenticate from A IDP else B IDP."  How can we achieve this ?
> I have not paying close attention to the many lines of metadata you
> sent, but that requirement seems new to me. Maybe I've missed it in
> your previous post.
>
> Either way, that sounds like a requirement for a SAML IDP Discovery
> Service (allowing to pick an IDP based on entering personal data, such
> as an email address, which I personally think is a stupid idea), not
> for a SAML proxy.
The only possible advantage of doing that inside the SAML proxy is user 
friendliness. That way the user does not have to enter his credentials 
(i.e. email) twice.
Basically [...]@example.org triggers an internal loginflow and requests 
the password for that account straight away, while every other hostname 
gets sent away to some external IdP, leveraging a "SAML proxy loginflow".
I think I've seen that done in simplesamlphp at some point where asking 
the user for information as few times as possible was the major concern.

Anyways, you will need a SAML proxy for that functionality regardless 
and Shibboleth is not one out of the box.

- David
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20180516/8cd5af82/attachment.html>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 2269 bytes
Desc: S/MIME Cryptographic Signature
URL: <http://shibboleth.net/pipermail/users/attachments/20180516/8cd5af82/attachment.p7s>


More information about the users mailing list