Multiple Vhosts - one end point

Aaron Roots aaron.roots at deakin.edu.au
Mon Oct 10 00:43:12 BST 2011


There is no need to differentiate the SP resources - standard set of
attributes are just available to internal SPs.

Reading this document
https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPApplicationMod
el - Has the line "Out of the box, all resources on all virtual hosts are
assigned to a fixed "base" application called "default" that uses a single
set of configuration options and runs as a single logical SP."

Without a clearer answer - I took this to mean that all vhosts are
associated with the one logical SP by default - and that then I would just
be able to define one base set of Metadata for the one logical SP at the
IdP - and everything else is fine. Of course it appears that it would be
happy with this as long as the SP was requesting the IdP to respond to
that one logical SP's endpoint.

But obviously I have misunderstood - and every time a new vhost get's
added to this server we will have to also add to the IdP or the metadata
new endpoints/SPs - as I am pulling the Metadata from the SPs default URL
- I am now hoping I can add endpoints to the SP side easily - will look
into this today.

Cheers for your help.
Aaron



On 10/10/11 3:37 AM, "Peter Schober" <peter.schober at univie.ac.at> wrote:

>* Cantor, Scott <cantor.2 at osu.edu> [2011-10-09 18:31]:
>> On 10/9/11 12:25 PM, "Peter Schober" <peter.schober at univie.ac.at> wrote:
>> >
>> >Are you're suggesting to enhance the IdP to allow policy
>> >(e.g. attribute filtering) decisions based on ACS URLs?
>> 
>> He's talking about AttributeConsumingService elements, not URLs.
>
>I misread it for AssertionConsumerService (hence "ACS URLs"), which is
>what I was talking about.
>
>Anyway, at this point it's unclear the OP even has the need to
>differentiate SP resources at the IdP so the main point was pointing
>out 3 ways of using several vhosts with one SP instance.
>-peter
>--
>To unsubscribe from this list send an email to
>users-unsubscribe at shibboleth.net



More information about the users mailing list