<div dir="ltr">Phil,<div><br></div><div>I've set up a Cognito user pool and configured our Shib IdP to authenticate users to it. I don't know if it is practical/possible to accept authentications from the dynamic set of IdPs in the InCommon Federation.  I know you can set up specific bilateral relationships between the user pool and SAML IdPs, so if you have a reasonable number of IdPs you want to do business with, it is probably an option.  The first 50 active users a month covered in the free tier. Each federated user beyond that is <span style="color:rgb(51,51,51);font-family:AmazonEmber,"Helvetica Neue",Helvetica,Arial,sans-serif;font-size:14px">$0.015 USD, so 150 users would be $1.50.</span></div><div><span style="color:rgb(51,51,51);font-family:AmazonEmber,"Helvetica Neue",Helvetica,Arial,sans-serif;font-size:14px"><br></span></div><div><span style="color:rgb(51,51,51);font-family:AmazonEmber,"Helvetica Neue",Helvetica,Arial,sans-serif;font-size:14px">Thanks,</span></div><div><span style="color:rgb(51,51,51);font-family:AmazonEmber,"Helvetica Neue",Helvetica,Arial,sans-serif;font-size:14px">Carl Waldbieser</span></div><div><span style="color:rgb(51,51,51);font-family:AmazonEmber,"Helvetica Neue",Helvetica,Arial,sans-serif;font-size:14px">ITS</span></div><div><span style="color:rgb(51,51,51);font-family:AmazonEmber,"Helvetica Neue",Helvetica,Arial,sans-serif;font-size:14px">Lafayette College</span></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Thu, Jun 10, 2021 at 2:49 PM Phil Tracy <<a href="mailto:ptracy@northwestern.edu">ptracy@northwestern.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">





<div lang="EN-US">
<div class="gmail-m_6311238996114449002WordSection1">
<p class="MsoNormal"><span style="font-size:10.5pt;font-family:"Segoe UI",sans-serif;color:rgb(31,73,125)">Hello,</span><span style="font-size:10.5pt;font-family:"Segoe UI",sans-serif"><u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:10.5pt;font-family:"Segoe UI",sans-serif"><u></u> <u></u></span></p>
<div style="border-top:none;border-right:none;border-left:none;border-bottom:1pt solid windowtext;padding:0in 0in 1pt">
<p class="MsoNormal"><span style="font-size:10.5pt;font-family:"Segoe UI",sans-serif">I’m passing this along from a developer colleague. If any of you have related experience and are willing to share, he’d very much appreciate talking with you - I can put you
 in touch. Since most/all of his partner schools are part of InCommon, I think SAML federation is an ideal solution for this application. The piece I don’t know how to advise him on is getting a SAML SP-like widget in front of the AWS Lambda stuff. Thanks!<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:10.5pt;font-family:"Segoe UI",sans-serif"><u></u> <u></u></span></p>
</div>
<p class="MsoNormal"><span style="font-size:10.5pt;font-family:"Segoe UI",sans-serif"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:10.5pt;font-family:"Segoe UI",sans-serif">We're developing a new application. Most of our users are part of Northwestern, but we occasionally need to collaborate with faculty members from other nearby universities,
 so they need to log in.<br>
<br>
The app is written in PHP and being deployed on AWS Lambda w/ API Gateway serving as the "web server". For Northwestern logins, we're using Azure AD's OAuth2 APIs and a PHP library to process the callback.<br>
<br>
I need to figure out the simplest way of permitting SAML logins from other universities. (From there, the app can do authorization -- it'll already know who has been invited to collaborate on a project.)<u></u><u></u></span></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">--<u></u><u></u></p>
<p class="MsoNormal">Phil Tracy<u></u><u></u></p>
<p class="MsoNormal">Lead Developer<u></u><u></u></p>
<p class="MsoNormal">Northwestern IT, Identity Services<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
</div>

-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>