Shibboleth as SAML Proxy

Peter Schober peter.schober at univie.ac.at
Mon Jul 5 14:30:40 UTC 2021


* Bergmann, Clemens <clemens.bergmann at tu-darmstadt.de> [2021-07-05 15:58]:
> One solution would be to configure a simplesaml as IdP on one side
> and federated SP on the other side. The application could use the
> IdP side to authenticate. Is such a setup also possible with
> Shibboleth?

I guess you'd find the SAML SP now built into the Shib IDP to be
insufficient for multi-party federating resources, but I haven't
looked at that myself.
(Also, the Shib IDP is not the most lightweight software in the world
if all you need is some SAML proxying, IMHO.)

Other than SimpleSAMLphp there's also SaToSa which (contrary to
SimpleSAMLphp) was specifcally desiged for that very use case.
(Though I'm personally spoiled by the Shib SP and so I invariably find
anything else to be lacking in one regard or another, incluing SaToSa.)

-peter


More information about the users mailing list