Should/Can SPs in multiple fed. metadata files use the same entityid for both?
Chris Phillips
Chris.Phillips at canarie.ca
Thu Aug 18 21:03:49 BST 2011
Hi all,
Checked out the archives and poked around the shib wiki and to me it looks like an SP that belongs to more than one federation should use the Chaining MetadataProvider configuration[1] to have both federations metadata available to the SP for evaluation.
The question I have is:
Can the SP be present with the same entityID in two (or more) metadata files from different federations provided the entityID record contents are identical and used in the identical fashion?
I would like the answer to be 'yes', but I'm leaning toward it being 'no' due to these comments, which are a bit difficult to unwind the meaning:
"While there is some limited capability for controlling the handling of duplicate entities, it is explicitly NOT supported for a single entityID to appear more than once with the same valid role, and the software will NOT behave predictably in such a case. In other words, if the same entity supports a given role, its metadata MUST be identical in all chained sources."
Can someone chime in on what an SP provider should do with their metadata to be included in multiple federations and if the Chaining Metadataprovider is not the right way, what is the right way?
Should it be a different entityID per federation metadata file?
Can it be the same entityID for all federation metadata files?
It may be useful to include these items in the documentation and if it is, just let me know what to look for…
Thanks!
Chris.
[1] https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPMetadataProvider
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20110818/21f839f0/attachment.html
More information about the users
mailing list