<html><body><div style="font-family: arial, helvetica, sans-serif; font-size: 10pt; color: #000000"><div data-marker="__QUOTED_TEXT__"><div style="font-family:'arial' , 'helvetica' , sans-serif;font-size:10pt;color:#000000"><div>Hi!<br></div><br><div>How we have done it at CSC - this is our in-house solution - is running a discovery flow first. The flow presents authentication options to the user as logos and text. See following on how it looks:<br></div><br><a href="https://notebooks.rahtiapp.fi/oauth2?rd=%2Foauth2">https://notebooks.rahtiapp.fi/oauth2?rd=%2Foauth2</a></div><div style="font-family:'arial' , 'helvetica' , sans-serif;font-size:10pt;color:#000000"><br data-mce-bogus="1"></div><div style="font-family:'arial' , 'helvetica' , sans-serif;font-size:10pt;color:#000000">1. First selection leads to Password flow</div><div style="font-family:'arial' , 'helvetica' , sans-serif;font-size:10pt;color:#000000">2. Second selection leads to SAML2 flow using Haka federation discovery</div><div style="font-family:'arial' , 'helvetica' , sans-serif;font-size:10pt;color:#000000">3. Third selection leads to SAML2 flow using Virtu federation discovery<br><br><div>The outcome of the selection for internal machinery is:</div></div><div style="font-family:'arial' , 'helvetica' , sans-serif;font-size:10pt;color:#000000"><br data-mce-bogus="1"></div><div style="font-family:'arial' , 'helvetica' , sans-serif;font-size:10pt;color:#000000">- Next flow to run. In our case usually saml2, oidc or password flow. Could be anything.<br><div>- Authenticating Authority. This we use only for saml2 and oidc flows i.e. flows that need to be informed of the upstream provider.<br></div><br><div>If the user has selected option that sets saml2 as next authentication flow we use information encoded to Authenticating Authority to set either upstream entity id in bean <code>shibboleth.authn.SAML.discoveryFunction</code> or upstream discovery in bean <code>shibboleth.authn.discoveryURLStrategy</code>.</div><br><div>The discovery flow <a href="https://github.com/CSCfi/shibboleth-idp-authn-discovery" target="_blank" rel="nofollow noopener noreferrer">https://github.com/CSCfi/shibboleth-idp-authn-discovery</a> has been used by us in some form since 2016 or for as long a we have been running Shibboleth based proxies. Unfortunately as it has been for in-house use only the documentation is scarce. If there is no generic solution for you and you want to have a go with this we are happy to document and maybe repackage the module as proper plugin. We have two digit number of shibboleth proxies running in different environments, most using this module as discovery.<br></div><div><br data-mce-bogus="1"></div><div> BR Janne<br data-mce-bogus="1"></div><br><br><br><hr id="zwchr"><div><b>From: </b>"Shib Users" <users@shibboleth.net><br><b>To: </b>"Shib Users" <users@shibboleth.net><br><b>Cc: </b>"Muhammad Farhan SJAUGI" <farhan@sifulan.my><br><b>Sent: </b>Tuesday, 17 October, 2023 02:38:38<br><b>Subject: </b>Discovery Service for Shibboleth IdP (as a Proxy)<br></div><br><div><div dir="ltr">Hi,<br><div>I am trying to set up Shibboleth IdP (as a Proxy IdP) and use SAML as the authentication protocol to the backend/actual authentication server. However, there are more than one authentication servers that the users can choose from to authenticate themself. Based on my "research" at Shibboleth IdP documentation, this is possible by either defining the <span style="color:rgb( 0 , 0 , 0 )">shibboleth.authn.SAML.discoveryFunction bean or pointing to some WAYF/DS service in the discoveryURL configuration. So, I am wondering if there is any (simple) embedded WAYF/DS solution that we can set up on the Shibboleth IdP server itself? either as a SAML.discoveryFunction or a WAYF/DS service (and set them at the discoveryURL).</span></div><div><span style="color:rgb( 0 , 0 , 0 )"><br></span></div><div><span style="color:rgb( 0 , 0 , 0 )">Thank you.</span></div><div><br clear="all"><div><div dir="ltr" class="gmail_signature"><div dir="ltr">--<div dir="ltr" style="color:rgb( 80 , 0 , 80 )"><font face="verdana, sans-serif" style="font-size:12.8px"><font color="#000000"><b>Ts. Muhammad Farhan Sjaugi, S.Kom. M.Sc.</b></font></font></div><div dir="ltr"><font face="verdana, sans-serif" style="color:rgb( 80 , 0 , 80 );font-size:12.8px"><font color="#666666"><b>VP (Engineering and Services)<br></b></font></font><div style="font-size:12.8px"><font color="#666666" face="verdana, sans-serif">SIFULAN Malaysian Access Federation</font></div><div style="color:rgb( 80 , 0 , 80 );font-size:12.8px"><font color="#666666"><font face="verdana, sans-serif">Email: <a href="mailto:farhan@sifulan.my" rel="nofollow noopener noreferrer nofollow noopener noreferrer" target="_blank">farhan@sifulan.my</a> | </font></font><span style="color:rgb( 102 , 102 , 102 );font-family:'verdana' , sans-serif">Website: <a href="https://www.sifulan.my" rel="nofollow noopener noreferrer nofollow noopener noreferrer" target="_blank">https://www.sifulan.my</a></span><br></div><div style="color:rgb( 80 , 0 , 80 );font-size:12.8px"><font color="#666666"><font face="verdana, sans-serif">PGP Fingerprint: 9AA0 1861 0921 3EBD 4E30 716A 1F71 FC55 49CD D06C</font></font></div><div style="color:rgb( 80 , 0 , 80 );font-size:12.8px"><font color="#666666"><font face="verdana, sans-serif">MBOT: GT20040131 | </font></font><font color="#666666"><font face="verdana, sans-serif">ORCID: </font></font><a href="https://orcid.org/0000-0001-8497-1768" rel="nofollow noopener noreferrer nofollow noopener noreferrer" target="_blank">https://orcid.org/0000-0001-8497-1768</a><br></div><div style="color:rgb( 80 , 0 , 80 );font-size:12.8px"><font color="#999999" style="font-size:small"><br></font></div></div></div></div></div></div></div>
<br>-- <br>For Consortium Member technical support, see https://shibboleth.atlassian.net/wiki/x/ZYEpPw<br>To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net</div></div><br></div></div></body></html>