We don't support IDP initiated authentication. If you can figure out how to do it using the Shib IDP, that's fine. But IDP initiated SSO is by definition a one-off configuration. Feel free to post your findings, but we don't recommend it.
Also, OpenID Connect does not support IDP initiated authentication, so it can lead to problems when you decide to upgrade to OAuth2.