Using Shibboleth IDP as a SAML proxy and handling unsolicited SSO
Cantor, Scott
cantor.2 at osu.edu
Mon Oct 13 13:57:45 UTC 2025
I don't really follow but indeed the IdP's proxying support does not itself allow an unsolicited response from the IdP being proxied.
The IdP's own unsolicited endpoint can be used normally however, there's nothing unusual about it. How authentication happens is the same regardless once it identifies the SP to issue a response to, whether it came from the SP or not.
The unsolicited enpdoint is nothing but a proprietary request message in the form of a query string instead of an XML message, there's nothing else fundamentally different.
-- Scott
More information about the users
mailing list