IdP-to-IdP Federation/Proxying TO a Shibboleth IdP?

o haya ohaya1001 at gmail.com
Mon Apr 7 16:49:26 UTC 2025


Hi,

I now have the new Shibboleth IdP working (authenticating against users in
an OpenDJ LDAP server, using password authentication) that I have been
posting about the last couple of weeks.

Prior to working on the Shibboleth IdP, I already had a test federation
environment working, with an SP ("SPA") and an IdP ("IdPA"), where "IdPA"
was authenticating users against a small DB.

Now that I have the new Shibboleth IdP, I want to re-configure the original
federation environment so that the "IdPA" basically delegates user
authentication to the Shibboleth IdP, and I was wondering:

    (a) is this possible to do with the Shibboleth IdP, and
    (b) in general, what do I need to do (in both the original SP+"IdPA"
IdP, and in the Shibboleth IdP) to accomplish this?

My apologies that all this is probably way too general, but I am just
starting to research this.

I've found some of the information in the Shibboleth Knowledge Base (e.g., "
https://shibboleth.atlassian.net/wiki/spaces/KB/pages/1459979597/Using+SAML+Proxying+to+another+IdP")
but those are kind of the "opposite" scenario, I think, i.e., they are
about using Shibboleth to proxy TO a different IdP, i.e, in my case I am
looking proxy TO the Shibboleth IdP.

Thanks in advance,
Jim




<https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=webmail>
Virus-free.www.avast.com
<https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=webmail>
<#DAB4FAD8-2DD7-40BB-A1B8-4E2AA1F9FDF2>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20250407/b2b6b7fc/attachment.htm>


More information about the users mailing list