IDP proxing for vendors non-DS/Wayf capabilities
Nate Klingenstein
ndk at signet.id
Mon Feb 1 21:53:18 UTC 2021
> In other cases, it can be a massive problem, as everything appears to the proxy as just a standard authentication request from one monolithic entityID with no cues beyond that.
And, similarly, the end SP only sees assertions as coming from a single IdP, In all cases, attributes are your lifeline, they're not going to be able to check scopes but you are, and logout is going to be an even bigger hairball than it usually is, as the proxying IdP only counts itself as a recipient of an assertion and AFAIK does not propagate logout requests received from the end SP back to the proxied IdP.
--------
Signet, Inc.
The Art of Access ®
https://www.signet.id
More information about the users
mailing list