> Yeah, I'm aware of that, and while not ideal, that may be acceptable. I'm
> not enthuastic about coaxing our sysadmins through the edits to the jre's
> security stuff that might be required though:
Then you can forgo any back-channel protocols with client TLS
authentication, or just don't rely on a Java web server (which means you
need Apache, meaning a different level of sysadmin involvement). There are a
variety of trade-offs.
You haven't described what actual use cases involving SAML you need, so
without knowing that in some detail, it's hard to identify what the actual
IdP requirements are (independent of Shibboleth per se).
-- Scott