What services does an intermediary (Vermittler, broker) offer in a hub-and-spoke federation, and what is always part of it?
The intermediary offers shared services to all IAM providers and relying parties in the federation, such as metadata management, IdP discovery, identity linking, transformation of authentication and attribute confirmations, and protocol transformation; an authentication proxy is always an integral part of it, and it may optionally contain an IdP of its own.
* The intermediary's shared services around its non-optional core, the authentication proxy. *
Possible central services:
- Metadata management: one registry of all participants, their endpoints and keys.
- IdP discovery: helping the user find the right IdP ("where are you from?").
- Identity linking: connecting a user's identities from different IdPs.
- Transformation of authentication and attribute confirmations: re-issuing assertions in the form the RP expects, mapping attribute names and assurance levels.
- Protocol transformation: accepting SAML on one side and issuing OpenID Connect on the other.
Since all of this requires the broker to terminate and re-issue authentication messages, the authentication proxy is its non-optional core. The broker may also run an IdP itself, in which case it is sometimes called a super-IdP. Synonyms: hub, broker, super-IdP.