<p dir="ltr">Thank you for the answers.<br>
@Eric: it wouldn't be an issue, but I was wondering: can the SP easily be configured to "point to" an IdP proxy instead of and IdP or yo a Discovery Service?<br>
</p>
<div class="gmail_quote">Il 18/apr/2016 19:31, "Eric Goodman" <<a href="mailto:Eric.Goodman@ucop.edu">Eric.Goodman@ucop.edu</a>> ha scritto:<br type="attribution"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div lang="EN-US" link="blue" vlink="purple">
<div>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1f497d">This can be done using an IdP Proxy. SimpleSamlPhp is one product you can use for this purposes. It has hooks for doing what you describe, but there would be
custom coding required.<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1f497d"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1f497d">The approach assumes you have a process to populate and maintain the extra information (e.g., entitlements) for users from all of the IdPs for the proxy to
pull information from. The Proxy doesn’t help at all with managing that extra information, it just offers a mechanism for “post processing” the SAML responses and injecting information before the SP gets the SAML response.
<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1f497d"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1f497d">Using an IdP Proxy approach, the SP sees all the attributes as coming from the IdP Proxy, not from the original source IdPs, so it’s not “transparent” to the
SP in that sense. It’s not clear from your description whether or not that would cause an issue for you.
<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1f497d"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1f497d">--- Eric<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1f497d"><u></u> <u></u></span></p>
<p class="MsoNormal"><b><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif"">From:</span></b><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif""> users [mailto:<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a>]
<b>On Behalf Of </b>Stefano Zanmarchi<br>
<b>Sent:</b> Monday, April 18, 2016 7:23 AM<br>
<b>To:</b> Shib Users<br>
<b>Subject:</b> IdP gateway<u></u><u></u></span></p>
<p class="MsoNormal"><u></u> <u></u></p>
<div>
<p class="MsoNormal">Hi all,<u></u><u></u></p>
<div>
<p class="MsoNormal">I'm looking for an IdP gateway with the ability to add attributes to those received from an IdP.<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">The scenario I'd like to achieve is:<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">- the user clicks on the SP's login button<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">- she gets redirected to the IdP gateway<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">- the IdP gateway presents the user with a list of IdPs she can chose from<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">- the user selects an IdP and authenticates<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">- upon succesful authentication the gateway returns the user to the SP adding some attributes (e.g. an entitlement).<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">Has something like this already been implemented, possibly open source? Any information would be greatly appreciated.<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">Thanks,<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">Stefano<u></u><u></u></p>
</div>
</div>
</div>
</div>
<br>--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br></blockquote></div>