Encryption-less SP to auth against encryption-mandating IdP?
Daniel Smith
danielesmith at gmail.com
Thu Jan 24 11:40:42 EST 2019
I'm new to Shibboleth as of today, and the documentation is a little
overwhelming. I was wondering if the following scenario is possible:
1. SP requires SAML 2.0 assertion for user groups to assign roles, but does
not support assertion decryption, nor metadata generation, nor authn
request signing
2. IdP mandates assertion encryption and authn request signing
3. Shibboleth hopefully sits in the middle, sending signed authn requests
to IdP and decrypted SAML assertions to SP
Ideally I'd like to use mod_shib as the SP already has Apache running. Is
there a walkthrough for this kind of scenario or do I just have to keep
reading? Or, is this kind of encryption-one-way-but-not-the-other not
supported?
Thanks,
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20190124/554a4c62/attachment.html>
More information about the users
mailing list