<div dir="ltr"><div><div><div><div><div><div><div><div><div>Hello,<br><br></div>I am 
exploring Shibboleth and am fairly new to SAML. I have installed both 
Shibboleth SP and Idp and tested them against TestShib. I have been 
looking at both SAML specification and also Shibboleth Confluence Wiki(a
 great resource). I have two questions that I have not been able to 
figure out:<br><br></div>1. IdpList element for SP<br></div>2. SAML Proxy Idp<br><br></div>Both
 questions relate to what is referred to as &#39;Idp Chaining&#39;, but the SAML
 specification defines it as SAML Idp Proxying. More details on the 
specific information I am looking for is below:<br><br></div>1. IdpList for SP<br></div>The
 SAML specification says that an &lt;IdpList&gt; element can list all 
the Idp&#39;s that the requester would need assertions from. Where, in 
Shibboleth SP configuration this can be specified(if at all it can be)? I
 would be grateful if I can be pointed to the wiki page that contains 
relevant information.<br><br></div>2. SAML Proxy Idp<br></div>Is there 
some specific configuration that Idp needs to act as a proxy Idp? Or is 
it from the Request that the Idp figures out that it needs to act as a 
proxy Idp(from &lt;ProxyCount&gt; and &lt;IdpList&gt; elements).<br><br></div>Thank you,<br>Sundeep </div>