IDP v4.2.1 - Using SAML Proxying to another IdP
prasanna cg
prasannacgin at yahoo.in
Mon May 23 19:12:25 UTC 2022
Thanks, Scott. I am doing this the first time. Thanks for correcting my understanding. In SAML Proxy, I am looking for further help on the following. Can you help / share guidance ?
1) If my upstream IDP is only sending the SAML Subject containing authenticated username (and no attribute statement), how can I map the incoming SAML Subject as SAML Subject in the Auth response from my Original IDP to the downstream SP ?
2) I am using authn\SAML in MFA flow (as my second factor), I would like to pass the authenticated principal from 1st factor in my Auth request to the upstream IDP. Where do I get to configure this mapping ?
3) How should I sign the SAML Auth request to the Upstream IDP ?
Many thanks in advance !
Thanks,
Prasanna
> On May 23, 2022, at 12:49 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:
>
> On 5/23/22, 12:36 PM, "users on behalf of prasanna cg via users" <users-bounces at shibboleth.net on behalf of users at shibboleth.net> wrote:
>
>> Do we have an equivalent article of
>> https://shibboleth.atlassian.net/wiki/spaces/KB/pages/1459979597/Using+SAML+Proxying+to+another+IdP
>> available for IDP v4.2 ? If not, can anyone help to highlight the key differences from a config standpoint ?
>
> The changes are related to 4.1, not 4.2, mostly that improvements were made to simplfy the configuration when pulling in an Attribute for subject c14n of the username so it's not as awkward. Everything before still works, but the documentation that you should be using, which isn't that, has updated examples for how to do it.
>
>> I did review the article -
>> https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/1282539600/SAMLAuthnConfiguration
>
> Then what didn't you understand in it?
>
>> I understood that SAML as an authentication flow is no longer applicable for 4.2
>
> That is untrue and there is nothing anywhere saying that in our documentation that I'm aware of.
>
> -- Scott
>
>
More information about the users
mailing list