<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body>
<div dir="ltr" style="font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt;">
Thank you Scott for your response. Sorry, I do tend to be verbose in my questions as to not leave out something that might be important.</div>
<div dir="ltr" style="font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt;">
<br>
</div>
<div dir="ltr" style="font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
As I expected, the unsolicited response will not work. Thanks for confirming that.</div>
<div dir="ltr" style="font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div dir="ltr" style="font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
The main problem I am trying to overcome is (while using the IDP as a SAML Proxy), Google Workspace’s SAML integration posts directly to the ACS endpoint without first getting an Authentication Request:</div>
<div dir="ltr" style="font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div dir="ltr" style="font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 16px; color: rgb(0, 0, 0);">
https://<domain>/idp/profile/Authn/SAML2/POST/SSO</div>
<div dir="ltr" style="font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt;">
<br>
</div>
<div dir="ltr" style="font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
The error resulting from this is: No RelayState parameter, unable to resume flow execution</div>
<div dir="ltr" style="font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div dir="ltr" style="font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Adding a RelayState, I get the error: Badly formatted flow execution key (because currently, there is no webflow)</div>
<div dir="ltr" style="font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div dir="ltr" style="font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Is it possible to start a WebFlow on a post to this ACS endpoint if none yet exists?</div>
<div dir="ltr" style="font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div dir="ltr" style="font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Thanks,</div>
<div dir="ltr" style="font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Dave.</div>
<div dir="ltr" style="font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt;">
<br>
</div>
<div dir="ltr" style="font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt;">
<br>
</div>
<div id="ms-outlook-mobile-signature" dir="ltr">
<div dir="ltr" style="color: rgb(0, 0, 0);"><a href="https://hihello.me/p/b3eb5b07-46c1-4835-a076-f3f308655e8f" target="_blank" rel="noopener" data-outlook-id="487690e4-c221-4b71-89f3-9631d6711bc8" style="display: inline-block; text-align: left;"><img src="https://cdn.hihello.me/cards/b3eb5b07-46c1-4835-a076-f3f308655e8f/signature_logo.png?generated=1753876713752" alt="This is David Rager's card. Their email is drager@instructionalempowerment.com. Their phone number is +1 814 580 5488." width="360" style="width: 360px; max-width: 396px; min-height: 100px; display: inline-block;"></a></div>
</div>
<div id="mail-editor-reference-message-container">
<div class="ms-outlook-mobile-reference-message skipProofing">
<meta name="Generator" content="Microsoft Exchange Server">
</div>
<div class="ms-outlook-mobile-reference-message skipProofing" style="text-align: left; padding: 3pt 0in 0in; border-width: 1pt medium medium; border-style: solid none none; border-color: rgb(181, 196, 223) currentcolor currentcolor; font-family: Aptos; font-size: 12pt; color: black;">
<b>From: </b>Cantor, Scott <cantor.2@osu.edu><br>
<b>Date: </b>Monday, October 13, 2025 at 9:57 AM<br>
<b>To: </b>Shib Users <users@shibboleth.net><br>
<b>Cc: </b>Dave Rager <drager@instructionalempowerment.com><br>
<b>Subject: </b>Re: Using Shibboleth IDP as a SAML proxy and handling unsolicited SSO<br>
<br>
</div>
<div class="PlainText" style="font-size: 11pt;">[You don't often get email from cantor.2@osu.edu. Learn why this is important at
<a href="https://aka.ms/LearnAboutSenderIdentification" data-outlook-id="42e3968c-8334-444f-be82-12ad867b8df4">
https://aka.ms/LearnAboutSenderIdentification</a> ]<br>
<br>
I don't really follow but indeed the IdP's proxying support does not itself allow an unsolicited response from the IdP being proxied.<br>
<br>
The IdP's own unsolicited endpoint can be used normally however, there's nothing unusual about it. How authentication happens is the same regardless once it identifies the SP to issue a response to, whether it came from the SP or not.<br>
<br>
The unsolicited enpdoint is nothing but a proprietary request message in the form of a query string instead of an XML message, there's nothing else fundamentally different.<br>
<br>
-- Scott<br>
<br>
<br>
</div>
</div>
</body>
</html>