Post saml reponse from one shib idp to other shib idp
David Huebner
david.huebner at daasi.de
Wed May 16 09:36:32 EDT 2018
On 15.05.2018 18:11, Peter Schober wrote:
>> So My requirement is that" if user enter this email then user should
>> authenticate from A IDP else B IDP." How can we achieve this ?
> I have not paying close attention to the many lines of metadata you
> sent, but that requirement seems new to me. Maybe I've missed it in
> your previous post.
>
> Either way, that sounds like a requirement for a SAML IDP Discovery
> Service (allowing to pick an IDP based on entering personal data, such
> as an email address, which I personally think is a stupid idea), not
> for a SAML proxy.
The only possible advantage of doing that inside the SAML proxy is user
friendliness. That way the user does not have to enter his credentials
(i.e. email) twice.
Basically [...]@example.org triggers an internal loginflow and requests
the password for that account straight away, while every other hostname
gets sent away to some external IdP, leveraging a "SAML proxy loginflow".
I think I've seen that done in simplesamlphp at some point where asking
the user for information as few times as possible was the major concern.
Anyways, you will need a SAML proxy for that functionality regardless
and Shibboleth is not one out of the box.
- David
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20180516/8cd5af82/attachment.html>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 2269 bytes
Desc: S/MIME Cryptographic Signature
URL: <http://shibboleth.net/pipermail/users/attachments/20180516/8cd5af82/attachment.p7s>
More information about the users
mailing list