Using Shibboleth IDP as a SAML proxy and handling unsolicited SSO

Cantor, Scott cantor.2 at osu.edu
Mon Oct 13 15:34:02 UTC 2025


> Is it possible to start a WebFlow on a post to this ACS
> endpoint if none yet exists?

That is literally what I was saying will not work, that's unsolicited SSO from the proxied IdP.

Unsolicited SSO from our IdP to an SP that subsequently proxies authentication to another IdP works fine. That's not what that is.

--Scott





More information about the users mailing list