Hi,<div>  I have been following the conversation regarding using a reverse proxy in front of a Shibboleth IDP and I&#39;m probing some possible workarounds. One of them includes modifying my IDP&#39;s metadata to report the internal host name rather than the front-facing proxy&#39;s host name. My intuition tells me this would not work but I can&#39;t find any documentation to support it one way the other.</div>

<div><br></div><div>if <font face="courier new, monospace"><a href="http://idpfrontproxy.example.edu">idpfrontproxy.example.edu</a></font> is changed to <font face="courier new, monospace"><a href="http://idpbackend.example.edu">idpbackend.example.edu</a></font> in my SAML EndPoints would it work or does the SP use the Location URL in IDP&#39;s metadata to determine what URL to use?</div>

<div><br></div><div><font face="courier new, monospace" size="1">&lt;AttributeService Binding=&quot;urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding&quot; Location=&quot;<a href="https://idpfrontproxy.example.edu/profile/SAML1/SOAP/AttributeQuery">https://idpfrontproxy.example.edu/profile/SAML1/SOAP/AttributeQuery</a>&quot;/&gt;</font><br clear="all">

<div style="font-family:tahoma,sans-serif"><font face="tahoma, sans-serif"><br></font></div><div><font face="arial, helvetica, sans-serif">Secondly, has anyone tried using the </font><font face="courier new, monospace">ResponseLocation </font><font face="arial, helvetica, sans-serif">optional field to use a communicating URL that differs from the EndPoint Location?</font></div>

<div style="font-family:tahoma,sans-serif"><font face="tahoma, sans-serif"><br></font></div><font face="tahoma, sans-serif">Joshua Riffle</font><div><font face="tahoma, sans-serif">Software Engineer<br></font><div><font color="#CC0000" face="tahoma, sans-serif"><b>Azusa Pacific University</b></font></div>

</div><br>
</div>