IdP-to-IdP Federation/Proxying TO a Shibboleth IdP?

Gianluca Amato gianluca.amato.74 at gmail.com
Wed Apr 23 09:04:23 UTC 2025


Sorry for the late reply—hope I can still be of help!

I'm having trouble understanding the difference between "proxying *to* a
different IdP" and "proxying *to* the Shibboleth IdP." In both scenarios,
there's an "authoritative" Shibboleth IdP and a "proxying" Shibboleth IdP
(which you're referring to as IdPA). This proxying IdP communicates with
the authoritative IdP on one side and with the Service Provider (SP) on the
other.

I have a similar setup myself. I use this configuration because the
"authoritative" Shibboleth IdP is partially outside of my control and
releases wrong values for attributes. So I rely on a proxy IdP to handle
communication with SPs that require special configurations or cleaned-up
attributes.

The guide I have followed is this one:
https://shibboleth.atlassian.net/wiki/spaces/IDP5/pages/3199505973/SAMLAuthnConfiguration

Best regards
--gianluca amato

On Mon, Apr 7, 2025 at 6:49 PM o haya via users <users at shibboleth.net>
wrote:

> Hi,
>
> I now have the new Shibboleth IdP working (authenticating against users in
> an OpenDJ LDAP server, using password authentication) that I have been
> posting about the last couple of weeks.
>
> Prior to working on the Shibboleth IdP, I already had a test federation
> environment working, with an SP ("SPA") and an IdP ("IdPA"), where "IdPA"
> was authenticating users against a small DB.
>
> Now that I have the new Shibboleth IdP, I want to re-configure the
> original federation environment so that the "IdPA" basically delegates user
> authentication to the Shibboleth IdP, and I was wondering:
>
>     (a) is this possible to do with the Shibboleth IdP, and
>     (b) in general, what do I need to do (in both the original SP+"IdPA"
> IdP, and in the Shibboleth IdP) to accomplish this?
>
> My apologies that all this is probably way too general, but I am just
> starting to research this.
>
> I've found some of the information in the Shibboleth Knowledge Base (e.g.,
> "
> https://shibboleth.atlassian.net/wiki/spaces/KB/pages/1459979597/Using+SAML+Proxying+to+another+IdP")
> but those are kind of the "opposite" scenario, I think, i.e., they are
> about using Shibboleth to proxy TO a different IdP, i.e, in my case I am
> looking proxy TO the Shibboleth IdP.
>
> Thanks in advance,
> Jim
>
>
>
>
>
> <https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=webmail>
> Virus-free.www.avast.com
> <https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=webmail>
> <#m_-8479414523727425081_DAB4FAD8-2DD7-40BB-A1B8-4E2AA1F9FDF2>
> --
> For Consortium Member technical support, see
> https://shibboleth.atlassian.net/wiki/x/ZYEpPw
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20250423/e2bd61c2/attachment.htm>


More information about the users mailing list