Using Shibboleth IDP as a SAML proxy and handling unsolicited SSO

Cantor, Scott cantor.2 at osu.edu
Mon Oct 13 15:38:14 UTC 2025


In other words:

SP = SP
IdP = Shibboleth
PIdP = IdP used via proxying by Shibboleth

PidP -> IdP -> SP = No
SP -> IdP -> PidP -> IdP -> SP = Yes (standard SSO)
IdP -> PidP -> IdP -> SP = Yes (unsolicited SSO)

-- Scott






More information about the users mailing list