We are trying to use Shib IdP in our product. Before that we want to have a better understanding of how it works.<br><br>One question we have is how IdP verifies the metadata? For example, when we are trying to establish a trust relationship with verious SPs what we need to check? and when an AuthnRequest coming, how to we know if the request comes from a trusted SP?<br>

<br>Can anybody also point out where is the code that handle this?<br><br>I have sync-ed all the IdP source code, but it seems not very easy to find it out without understanding the whole thing.<br><br>Another question is apart from this: <a href="https://wiki.shibboleth.net/confluence/display/SHIB2/IdPHLA">https://wiki.shibboleth.net/confluence/display/SHIB2/IdPHLA</a>, is there any other resources to describe the overall design or architecture?<br>

<br>Your input is highly appreciated.<br><br><br>Best,<br clear="all">Yaowen<br>