Shibboleth IDP v4.2 : Disable AuthContextClassRef Check in SAML Proxying

Prasanna CG prasannacgin at yahoo.co.in
Thu Jul 28 03:54:41 UTC 2022


Hello,

Reaching out for help. I have the following request / response sequence in our SAML proxy setup of Shibboleth IDP. 

Scenario:
SP <=> Downstream IDP <=> Upstream IDP <=> Third Party IDP

In above, “Downstream IDP” is Shibboleth IDP v4.2

In this process, the SP first requests authcontext of “Password Protected“ in the auth request. The same gets preserved up to Third Party IDP which completes the AuthN and returns a custom authcontextclassref. This value is preserved up to the Downstream IDP that returns an error to the SP due to the difference in contextclassref between its  request and response from Upstream IDP.  

Question: Is there a configuration in Shibboleth IDP that allows me to disable this check and simply return the originally requested contextclassref (password protected) ? 


Thanks,
Prasanna
(Sent from mobile device, please ignore typos)
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20220728/7af4a463/attachment.htm>


More information about the users mailing list