<div dir="ltr"><div dir="ltr"><br></div><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
I guess you'd find the SAML SP now built into the Shib IDP to be<br>
insufficient for multi-party federating resources, but I haven't<br>
looked at that myself.<br></blockquote><div><br></div><div>There are various ways to build discovery into the IdP.  We've done this for several services, such as AWS Cognito, including automatically scripting different SP's to route directly to specific IdP's.<br></div><div><br></div><div>It isn't too painful, though you lose some options and complicate the deployment by necessity when proxying.  It should meet Clemens' use case, but...</div><div><br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
(Also, the Shib IDP is not the most lightweight software in the world<br>
if all you need is some SAML proxying, IMHO.)<br></blockquote><div><br></div><div>I agree with the simpleSAMLphp suggestion.<br></div></div></div>