Multiple entity-id:s for SP-half of IdP?
Tomas Stenlund
tomas.stenlund at telia.com
Sun Mar 31 07:15:53 UTC 2024
Hi,
In the online documentation for SAMLAuthConfiguration it states that: On
the SP "half" of the IdP that the IdP's entityID is presumed to be the
same one applying to normal outbound use, but can be overridden if
required. In mys etup I am only proxying, using Shibboleth IdP 5.1.1.
How is the override done? I haven't been able to find out how.
Related to the above and this might sound like a stupid question. In the
SAML-federation, i am using, the set of attributes released from the
IdP:s in the federation is controlled by an entityattribute in the
SP-metadata registered by my proxy in the federation. I want to have the
minimum amount of data released from the upstream IdP:s. Some of the
values in the entityattribute that controls the set of attributes is
honored by IdP:s that can release both sets causing some of the IdP:s to
release more than nessecary for my SP. Resulting in asking the user to
give consent for more than is needed.
Based on that, is it possible to have the Shibboleth IdP act as multiple
SP-halfs, i.e. use different entityId:s based on which IdP it is
proxying to upstream. Then I could register multiple SP-metadata in the
federation and control it that way.
Any other idea? I guess two proxies would solve it as well, but makes
deployment and user interaction a bit more complex.
Thanks,
Tomas
More information about the users
mailing list