<div dir="ltr"><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">What do you mean by one to many?<br></blockquote><div><br></div><div>Hopefully an example will clarify:</div><div><br></div><div>                &lt;bean class=&quot;net.shibboleth.idp.cas.service.ServiceDefinition&quot;</div><div>                      c:regex=&quot;https://([A-Za-z0-9_-]+\.)*vt\.edu(:\d+)?/.*&quot;</div><div>                      p:group=&quot;standard-vt-services&quot;</div><div>                      p:authorizedToProxy=&quot;false&quot; /&gt; </div><div><br></div><div>That allows all secure services in the VT DNS namespace to use CAS. That is the single most common use of the service registry: to restrict SSO to institutional boundaries.</div><div><br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">I was led to understand that the norm in CAS is to apply no controls and not register services at </blockquote><div><br></div><div>While that may have been true in the past, I&#39;m fairly certain it&#39;s more common these days to restrict at least to institutional boundaries.<a href="mailto:dev-unsubscribe@shibboleth.net" target="_blank"></a><br>
</div><div><br></div><div>M</div><div><br></div></div></div>