<div dir="ltr"><div class="gmail_extra"><br><div class="gmail_quote">On Tue, Mar 12, 2013 at 7:37 PM, Eric Goodman <span dir="ltr"><<a href="mailto:Eric.Goodman@ucop.edu" target="_blank">Eric.Goodman@ucop.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class=""><br>
</span>We're looking at implementing this in a case where multiple cloud-hosted vendors (each of which supports SAML assertions, but their discovery services are lacking) are each trying to integrate with a defined (i.e., fixed membership) federation of IdPs.</blockquote></div><br>We're considering adding an IdP proxy to allow us to provide social-to-SAML services (in addition to our own IdP) to cloud providers who can / will only be configured to talk to a single IdP. I'd rather not, but I can't think of another solution for those sites.</div><div class="gmail_extra"><br></div><div class="gmail_extra">Liam</div></div>