<html><body><div style="font-family: arial, helvetica, sans-serif; font-size: 12pt; color: #000000"><div style="font-family: arial, helvetica, sans-serif; font-size: 12pt; color: #000000"><div>Hello,<br data-mce-bogus="1"></div><div><br data-mce-bogus="1"></div><div>recently, (thanks to the list!), I enabled IDP-proxying for DocuSign SP , cf : https://marc.info/?t=161193758600001&r=1&w=2<br></div><div>Now , although everyhting works fine for most of the IDPs behind the IDP-Proxy , some clients that uses private IPs + NAT cannot complete the SSO+attributes complete process . <br></div><div>I suspect that in the long workflow of redirects , they hit a missmatch between the browser private IP @ and the one NATed viewed by the SP and /or Proxy ...<br></div><div>I found the in the SP doc: <a href="https://wiki.shibboleth.net/confluence/display/SP3/Sessions">https://wiki.shibboleth.net/confluence/display/SP3/Sessions</a> the <code>checkAddress</code> attribute that might be the "culprit" ? <br data-mce-bogus="1"></div><div>but this is a SP attribute , how can I tell my IDP-Proxy that act as a SP for 2nd hand IDPs not to checkaddresses ? (if this is the real culprit ? ) <br data-mce-bogus="1"></div><div><br data-mce-bogus="1"></div><div>thanks<br data-mce-bogus="1"></div><div><br data-mce-bogus="1"></div><br></div></div></body></html>