Shibboleth IdP 4, SAML proxying and SimpleSAMLphp proxy breakage?

Robert Bradley robert.bradley at it.ox.ac.uk
Tue Feb 23 18:52:57 UTC 2021


On 23/02/2021 17:07, Cantor, Scott wrote:
> I did verify (both while writing the code and just now) that the rule in SAML is to add the "latest" IdP at the end of the list of AuthenticatingAuthority elements.
> 
> I can't say I have any clear idea what on earth they're doing with the name qualifiers but it sounds like maybe they're looking at the elements in the wrong order.
> 

My guess is that they're picking the first AuthenticatingAuthority in 
the list, which works fine if your first IdP is authoritative for 
eduPersonTargetedID, and breaks if it's not.

My gut says the "correct" behaviour should be to use the last 
AuthenticatingAuthority or Issuer instead, but I can see that breaking 
with hub-spoke federations like SURFconext.  Another option would be to 
just take the NameQualifier attribute from the NameID (if present) and 
use that.

-- 
Dr Robert Bradley
Identity and Access Management Team, IT Services, University of Oxford

-------------- next part --------------
A non-text attachment was scrubbed...
Name: OpenPGP_signature
Type: application/pgp-signature
Size: 840 bytes
Desc: OpenPGP digital signature
URL: <http://shibboleth.net/pipermail/users/attachments/20210223/2bf41d98/attachment.sig>


More information about the users mailing list