Is it possible to configure python3-saml to use a WAYF/discovery service with shibboleth and how would the configuration for that look like? Like a matching config for something like
But if you plan to support multiple IdPs in your app, there is many ways to support the way IdPs gonna be discovered:
In a multi tenancy environment, use subdomain or URL path to isolate customers and related IdPs.
In a single environment, use GET parameters on the SAML endpoints to determine what IdPs should be used, and discover this by extending login page and :
a) Offer user a list of different IdPs to be accessed via click.
b) Ask user for email, and use the email domain to relate to a specific customer and related IdP.
Is it possible to configure python3-saml to use a WAYF/discovery service with shibboleth and how would the configuration for that look like? Like a matching config for something like