Shibboleth IdP 4, SAML proxying and SimpleSAMLphp proxy breakage?
Robert Bradley
robert.bradley at it.ox.ac.uk
Tue Feb 23 18:52:57 UTC 2021
On 23/02/2021 17:07, Cantor, Scott wrote:
> I did verify (both while writing the code and just now) that the rule in SAML is to add the "latest" IdP at the end of the list of AuthenticatingAuthority elements.
>
> I can't say I have any clear idea what on earth they're doing with the name qualifiers but it sounds like maybe they're looking at the elements in the wrong order.
>
My guess is that they're picking the first AuthenticatingAuthority in
the list, which works fine if your first IdP is authoritative for
eduPersonTargetedID, and breaks if it's not.
My gut says the "correct" behaviour should be to use the last
AuthenticatingAuthority or Issuer instead, but I can see that breaking
with hub-spoke federations like SURFconext. Another option would be to
just take the NameQualifier attribute from the NameID (if present) and
use that.
--
Dr Robert Bradley
Identity and Access Management Team, IT Services, University of Oxford
-------------- next part --------------
A non-text attachment was scrubbed...
Name: OpenPGP_signature
Type: application/pgp-signature
Size: 840 bytes
Desc: OpenPGP digital signature
URL: <http://shibboleth.net/pipermail/users/attachments/20210223/2bf41d98/attachment.sig>
More information about the users
mailing list