LOGBOOK

HELP

Quiz Entry - updated: 2026.09.17

What is an authentication proxy, and why does it make end-to-end encryption difficult?

An authentication proxy connects two protocol segments and thereby forms a protocol endpoint: it can transform or adapt an authentication request and forward it to an IdP. Because it terminates the protocol on both sides, messages are decrypted and re-encrypted at the proxy, so true end-to-end encryption between RP and IdP is hard to achieve.

Relying party and identity provider each connected to the intermediary by protocol segments P1 and P2, with no direct segment P3

* Two protocol segments meet at the proxy, so nothing runs end to end between RP and IdP. *

In the diagram the RP talks to the broker over protocol segment P1, the broker talks to the IdP over segment P2, and there is no direct segment P3 between RP and IdP.

Being an endpoint rather than a pass-through is what makes the proxy useful (it can translate between protocols and rewrite assertions) and what creates the security consideration: the proxy sees the plaintext of every authentication confirmation and attribute it forwards. The federation therefore has to trust the broker not only to be honest but to be well protected, since compromising it means compromising every login that passes through.

Go deeper:

From Quiz: IAM / IAM Models: Topologies, Federation and Provisioning | Updated: Sep 17, 2026