Multiple entity-id:s for SP-half of IdP?

Tomas Stenlund tomas.stenlund at telia.com
Sun Mar 31 07:15:53 UTC 2024


Hi,

In the online documentation for SAMLAuthConfiguration it states that: On 
the SP "half" of the IdP that the IdP's entityID is presumed to be the 
same one applying to normal outbound use, but can be overridden if 
required. In mys etup I am only proxying, using Shibboleth IdP 5.1.1.

How is the override done? I haven't been able to find out how.

Related to the above and this might sound like a stupid question. In the 
SAML-federation, i am using, the set of attributes released from the 
IdP:s in the federation is controlled by an entityattribute in the 
SP-metadata registered by my proxy in the federation. I want to have the 
minimum amount of data released from the upstream IdP:s. Some of the 
values in the entityattribute that controls the set of attributes is 
honored by IdP:s that can release both sets causing some of the IdP:s to 
release more than nessecary for my SP. Resulting in asking the user to 
give consent for more than is needed.

Based on that, is it possible to have the Shibboleth IdP act as multiple 
SP-halfs, i.e. use different entityId:s based on which IdP it is 
proxying to upstream. Then I could register multiple SP-metadata in the 
federation and control it that way.

Any other idea? I guess two proxies would solve it as well, but makes 
deployment and user interaction a bit more complex.

Thanks,

Tomas



More information about the users mailing list