IDP v4.2.1 - Using SAML Proxying to another IdP

Cantor, Scott cantor.2 at osu.edu
Wed May 25 12:42:02 UTC 2022


> All SaaS based MFA providers supporting SAML based Authentication requires the 1st factor authenticated
> subject to be sent in the Auth request as part of the SAML Subject element.

That's news to me (*), but if that's how they're doing it, that's reasonably compliant with the original meaning and I would be willing to support it, but the only way to do that is to encode the username into a NameID.

> Also, Is there a plan to support that in the future ? 

If it's filed as a request, at some point.

-- Scott

(*) My impression is that it's normally done in a proprietary way, and no, we're not supporting that (explicitly anyway).




More information about the users mailing list