<div dir="ltr"><div><div><div><div><div><div><div><div><div>Hello,<br><br></div>I am
exploring Shibboleth and am fairly new to SAML. I have installed both
Shibboleth SP and Idp and tested them against TestShib. I have been
looking at both SAML specification and also Shibboleth Confluence Wiki(a
great resource). I have two questions that I have not been able to
figure out:<br><br></div>1. IdpList element for SP<br></div>2. SAML Proxy Idp<br><br></div>Both
questions relate to what is referred to as 'Idp Chaining', but the SAML
specification defines it as SAML Idp Proxying. More details on the
specific information I am looking for is below:<br><br></div>1. IdpList for SP<br></div>The
SAML specification says that an <IdpList> element can list all
the Idp's that the requester would need assertions from. Where, in
Shibboleth SP configuration this can be specified(if at all it can be)? I
would be grateful if I can be pointed to the wiki page that contains
relevant information.<br><br></div>2. SAML Proxy Idp<br></div>Is there
some specific configuration that Idp needs to act as a proxy Idp? Or is
it from the Request that the Idp figures out that it needs to act as a
proxy Idp(from <ProxyCount> and <IdpList> elements).<br><br></div>Thank you,<br>Sundeep </div>