saml proxying scoped attributes...best practice

Bobby Lawrence robertl at jlab.org
Wed Nov 13 15:31:03 UTC 2024


I'm not looking for the proxy to solve the discovery (loading large metadata) issue.  I'm looking for the proxy to provide unified authentication gateway for our services.  One that I can configure along side our SPs to provide a customized authentication experience for our users.

> -----Original Message-----
> From: Cantor, Scott <cantor.2 at osu.edu>
> Sent: Wednesday, November 13, 2024 9:44 AM
> To: Bobby Lawrence <robertl at jlab.org>; Shib Users <users at shibboleth.net>
> Subject: [EXTERNAL] Re: saml proxying scoped attributes...best practice
> 
> > The MDQ is great for IdPs to fetch metadata for SPs on the fly, but
> > the reverse isn't ideal. SPs need to know all IdP metadata up front in
> > order to provide discovery and the MDQ doesn't really work for that.
> 
> There are other discovery solutions (SeamlessAccess) and there are ways to produce the discovery feed without using the SP itself. That
> particular model isn't viable, obviously, and it's not all that much more viable on the IdP than the SP, so proxying doesn't really solve
> that.
> 
> -- Scott
> 



More information about the users mailing list