Shibboleth as SAML Proxy
Nate Klingenstein
ndk at signet.id
Tue Jul 6 04:44:29 UTC 2021
(And in theory, you could probably collapse all those use cases into a single IdP, but I don't know that you'd gain much from doing so. Implementing it would be probably more effort than setting up and maintaining the proxy IdP. That said, YMMV, so I could think of an MFA-defaulting IdP that decided which authentication flow to use based on the SP and applied an overridden entityID to those entityID's.)
More information about the users
mailing list