Hi,<div> I have been following the conversation regarding using a reverse proxy in front of a Shibboleth IDP and I'm probing some possible workarounds. One of them includes modifying my IDP's metadata to report the internal host name rather than the front-facing proxy's host name. My intuition tells me this would not work but I can't find any documentation to support it one way the other.</div>
<div><br></div><div>if <font face="courier new, monospace"><a href="http://idpfrontproxy.example.edu">idpfrontproxy.example.edu</a></font> is changed to <font face="courier new, monospace"><a href="http://idpbackend.example.edu">idpbackend.example.edu</a></font> in my SAML EndPoints would it work or does the SP use the Location URL in IDP's metadata to determine what URL to use?</div>
<div><br></div><div><font face="courier new, monospace" size="1"><AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="<a href="https://idpfrontproxy.example.edu/profile/SAML1/SOAP/AttributeQuery">https://idpfrontproxy.example.edu/profile/SAML1/SOAP/AttributeQuery</a>"/></font><br clear="all">
<div style="font-family:tahoma,sans-serif"><font face="tahoma, sans-serif"><br></font></div><div><font face="arial, helvetica, sans-serif">Secondly, has anyone tried using the </font><font face="courier new, monospace">ResponseLocation </font><font face="arial, helvetica, sans-serif">optional field to use a communicating URL that differs from the EndPoint Location?</font></div>
<div style="font-family:tahoma,sans-serif"><font face="tahoma, sans-serif"><br></font></div><font face="tahoma, sans-serif">Joshua Riffle</font><div><font face="tahoma, sans-serif">Software Engineer<br></font><div><font color="#CC0000" face="tahoma, sans-serif"><b>Azusa Pacific University</b></font></div>
</div><br>
</div>