Post saml reponse from one shib idp to other shib idp

Peter Schober peter.schober at univie.ac.at
Wed May 16 10:06:35 EDT 2018


* David Huebner <david.huebner at daasi.de> [2018-05-16 15:37]:
> The only possible advantage of doing that inside the SAML proxy is
> user friendliness. That way the user does not have to enter his
> credentials (i.e.  email) twice.

I thought asking for email was only done to get the subject to type
the DNS domain of their IDP (i.e., it's only about phrasing this in a
way that the subject should be able to understand, not about the
user-identifying part and certainly not about entering the password in
more than one place?

I.e., the purpose of this process seems to be to replace
typeahead-style UI components (to interactively determine the IDP
based on some identifying information, could be display name, parts of
the entityID, etc.) with "type your DNS domain and hit enter", and
then either failing that with an error ("Cannot find the IDP") or
start the SAML2 login flow to the IDP, hopefully the one the subject
intended.
Only there would I enter my identifying information ("credentials").

-peter


More information about the users mailing list