Using Shibboleth IDP as a SAML proxy and handling unsolicited SSO

Dave Rager drager at instructionalempowerment.com
Mon Oct 13 15:36:04 UTC 2025


Ok, thank you for the clarification. Much appreciated.

Dave.



[This is David Rager's card. Their email is drager at instructionalempowerment.com. Their phone number is +1 814 580 5488.]<https://hihello.me/p/b3eb5b07-46c1-4835-a076-f3f308655e8f>
From: Cantor, Scott <cantor.2 at osu.edu>
Date: Monday, October 13, 2025 at 11:34 AM
To: Shib Users <users at shibboleth.net>
Cc: Dave Rager <drager at instructionalempowerment.com>
Subject: Re: Using Shibboleth IDP as a SAML proxy and handling unsolicited SSO

[You don't often get email from cantor.2 at osu.edu. Learn why this is important at https://aka.ms/LearnAboutSenderIdentification ]

> Is it possible to start a WebFlow on a post to this ACS
> endpoint if none yet exists?

That is literally what I was saying will not work, that's unsolicited SSO from the proxied IdP.

Unsolicited SSO from our IdP to an SP that subsequently proxies authentication to another IdP works fine. That's not what that is.

--Scott



-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20251013/cc7b4954/attachment.htm>


More information about the users mailing list