<html><body><div style="color:#000; background-color:#fff; font-family:HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, Sans-Serif;font-size:14px"><div id="yui_3_16_0_1_1425847200632_10432" dir="ltr">Hi,</div><div id="yui_3_16_0_1_1425847200632_10432" dir="ltr"><br></div><div id="yui_3_16_0_1_1425847200632_10432" dir="ltr">I need to broker a 3rd party IdP(IdP2) which uses SAMLv2 browser profile with artifact resolution step and provides a web UI for login.</div><div id="yui_3_16_0_1_1425847200632_10432" dir="ltr"><br></div><div id="yui_3_16_0_1_1425847200632_10432" dir="ltr">In this brokerage I would be the SAMLv2 (simple browser profile) IdP (IdP1) to my service provider partner (SP1) and be reliant on the login web UI that the 3rd party (IdP2) presents for authenticating users.</div><div id="yui_3_16_0_1_1425847200632_10432" dir="ltr"><br></div><div id="yui_3_16_0_1_1425847200632_10432" dir="ltr">The goals:</div><div id="yui_3_16_0_1_1425847200632_10432" dir="ltr">- provide a common simple browser profile identity federation with the external Service Provider.</div><div id="yui_3_16_0_1_1425847200632_10432" dir="ltr">- keep the two circles of trust separate and exchange "userid" at the broker (not expose the userid from IdP2 to the SP1 but generate a pseudo ID instead and look it up from persisted source e.g. ldap directory).</div><div id="yui_3_16_0_1_1425847200632_10432" dir="ltr"><br></div><div id="yui_3_16_0_1_1425847200632_10432" dir="ltr"><br></div><div id="yui_3_16_0_1_1425847200632_10432" dir="ltr">Is this achievable with "back to back" connection of Shibboleth Identity and Service Provider instances?</div><div id="yui_3_16_0_1_1425847200632_10432" dir="ltr"><br></div><div id="yui_3_16_0_1_1425847200632_10432" dir="ltr">Any advice would appreciated. I could provide a high level sequence diagram if required.</div><div id="yui_3_16_0_1_1425847200632_10432" dir="ltr"><br></div><div id="yui_3_16_0_1_1425847200632_10432" dir="ltr">Cheers,</div><div id="yui_3_16_0_1_1425847200632_10432" dir="ltr">David.&nbsp;</div><div id="yui_3_16_0_1_1425847200632_10432" dir="ltr"><br></div><div id="yui_3_16_0_1_1425847200632_10432" dir="ltr"><br></div></div></body></html>