<div dir="ltr"><div>Sorry for the late reply—hope I can still be of help!</div><div></div><div><p class="gmail-">I'm having trouble understanding the difference between "proxying <em>to</em> a different IdP" and "proxying <em>to</em> the Shibboleth IdP." In both scenarios, there's an "authoritative" Shibboleth IdP and a "proxying" Shibboleth IdP (which you're referring to as IdPA). This proxying IdP communicates with the authoritative IdP on one side and with the Service Provider (SP) on the other.</p>
<p class="gmail-">I have a similar setup myself. I use this configuration because the "authoritative" Shibboleth IdP is partially outside of my control and releases wrong values for attributes. So I rely on a proxy IdP to handle communication with SPs that require special configurations or cleaned-up attributes.</p></div><div><br></div><div>The guide I have followed is this one: <a href="https://shibboleth.atlassian.net/wiki/spaces/IDP5/pages/3199505973/SAMLAuthnConfiguration">https://shibboleth.atlassian.net/wiki/spaces/IDP5/pages/3199505973/SAMLAuthnConfiguration</a></div><div></div><div><br></div><div>Best regards</div><div>--gianluca amato</div></div><br><div class="gmail_quote gmail_quote_container"><div dir="ltr" class="gmail_attr">On Mon, Apr 7, 2025 at 6:49 PM o haya via users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="ltr"><div>Hi,</div><div><br></div><div>
<div>
I now have the new Shibboleth IdP working (authenticating against users in an OpenDJ LDAP server, using password authentication) that I have been posting about the last couple of weeks.</div>

</div><div><br></div><div>Prior to working on the Shibboleth IdP, I already had a test federation environment working, with an SP ("SPA") and an IdP ("IdPA"), where "IdPA" was authenticating users against a small DB.</div><div><br></div><div>Now that I have the new Shibboleth IdP, I want to re-configure the original federation environment so that the "IdPA" basically delegates user authentication to the Shibboleth IdP, and I was wondering:</div><div><br></div><div>    (a) is this possible to do with the Shibboleth IdP, and </div><div>    (b) in general, what do I need to do (in both the original SP+"IdPA" IdP, and in the Shibboleth IdP) to accomplish this?</div><div><br></div><div>My apologies that all this is probably way too general, but I am just starting to research this.  </div><div><br></div><div>I've found some of the information in the Shibboleth Knowledge Base (e.g., "<a href="https://shibboleth.atlassian.net/wiki/spaces/KB/pages/1459979597/Using+SAML+Proxying+to+another+IdP" target="_blank">https://shibboleth.atlassian.net/wiki/spaces/KB/pages/1459979597/Using+SAML+Proxying+to+another+IdP</a>") but those are kind of the "opposite" scenario, I think, i.e., they are about using Shibboleth to proxy TO a different IdP, i.e, in my case I am looking proxy TO the Shibboleth IdP.</div><div><br></div><div>Thanks in advance,</div><div>Jim</div><div><br></div><div><br></div><div><br></div></div><div id="m_-8479414523727425081DAB4FAD8-2DD7-40BB-A1B8-4E2AA1F9FDF2"><br><table style="border-top:1px solid rgb(211,212,222)"><tbody><tr><td style="width:55px;padding-top:13px"><a href="https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=webmail" target="_blank"><img src="https://s-install.avcdn.net/ipm/preview/icons/icon-envelope-tick-round-orange-animated-no-repeat-v1.gif" alt="" width="46" height="29" style="width: 46px; height: 29px;"></a></td><td style="width:470px;padding-top:12px;color:rgb(65,66,78);font-size:13px;font-family:Arial,Helvetica,sans-serif;line-height:18px">Virus-free.<a href="https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=webmail" style="color:rgb(68,83,234)" target="_blank">www.avast.com</a></td></tr></tbody></table><a href="#m_-8479414523727425081_DAB4FAD8-2DD7-40BB-A1B8-4E2AA1F9FDF2" width="1" height="1"></a></div>
-- <br>
For Consortium Member technical support, see <a href="https://shibboleth.atlassian.net/wiki/x/ZYEpPw" rel="noreferrer" target="_blank">https://shibboleth.atlassian.net/wiki/x/ZYEpPw</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>