I thought I knew the answer to this question but now I'm not so sure... Suppose a Shib IdP supports SAML2 IdP-initiated SSO only. What does its metadata look like? Since an IDPSSODescriptor MUST include at least one SingleSignOnService endpoint, I'm not sure how to answer that question. Seems the only option is to define a custom RoleDescriptor. Tom