Configuring two applications within one Shibboleth installation

Cantor, Scott cantor.2 at osu.edu
Thu Jun 13 10:35:28 EDT 2013



> -----Original Message-----
> From: users-bounces at shibboleth.net [mailto:users-
> bounces at shibboleth.net] On Behalf Of Peter Schober
> Sent: Thursday, June 13, 2013 10:08 AM
> To: users at shibboleth.net
> Subject: Re: Configuring two applications within one Shibboleth installation
> 
> * Maassen, Helma <Helma.Maassen at atos.net> [2013-06-13 09:27]:
> > What I didn't mention before is that my SPs also need to be
> > different for the two IDPs, so a different Issuer in the
> > AuthnRequest, probably a different TrustEngine, probably even a
> > different AssertionConsumerService "type".
> 
> That's something else, of course. If you need different issuers you'll
> need seperate logocal SPs and hence ApplicationOverrides, yes.

I very much doubt you need a different Trust Engine or different "type" of ACS, not even sure what that would mean.

You definitely don't need it to override your own entityID in the majority of cases. Add a RelyingParty element for the IdP in question and set entityID there to override your SP's name for that IdP.

https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPRelyingParty

-- Scott




More information about the users mailing list