IDP 4.3 and non URL SP entity IDs

Michael Grady mgrady at unicon.net
Thu Jan 19 22:17:58 UTC 2023


SimpleSAML can, and has for as long as I've had any exposure to it (starting in 2013). But if one wanted to proxy to an ADFS IdP, one had to omit the Scoping element because ADFS would reject any AuthRequest with a Scoping element  in it.

> On Jan 19, 2023, at 4:13 PM, Cantor, Scott via users <users at shibboleth.net> wrote:
> 
>> So by setting this property to true, I risk not conforming to proxying standards,
>> but little else, correct?
> 
> Most likely, especially because the kind of proxying you're doing is one of those things that's not really true proxying. It's your Azure IdP, it's not a different organization's IdP. 
> 
> The reason I plugged the hole is policy. If you proxy to a Shibboleth IdP, that IdP can detect and enforce rules based on the original SP if you want it to. I'm sure we are the only IdP in the world that can without plowing into the XML.
> 
>> I'm considering creating a condition bean that returns true if the entity ID of the
>> SP isn't a URN or URL format as to not break Azure but false otherwise, but I'm
>> wondering if it's worth it.
> 
> I doubt it.
> 
> -- Scott
> 
> 
> -- 
> For Consortium Member technical support, see https://shibboleth.atlassian.net/wiki/x/ZYEpPw
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net

--
Michael A. Grady
IAM Architect, Unicon, Inc.





More information about the users mailing list