Hostname patch for Shibboleth IDP 2.4.0
Peter Schober
peter.schober at univie.ac.at
Thu Nov 21 07:26:42 EST 2013
* Guest, Simon <simon.guest at agresearch.co.nz> [2013-11-19 23:19]:
> Without this patch, generating the scope from the hostname fails, as
> it only expects a single dot in the scope.
Note that while will reduce the number of incorrectly guessed scopes
for new installes (esp. for ccTLDs with heirarchies in them, such as
co.nz or ac.uk) the scope cannot be determined correctly
automatically, period.
It might be completely different from the IdP's FQDN, or the new
domain component from your patch might actually be
unwanted/nonsensical to have in a scope (e.g. you might want to have
the IdP in the test. zone issue scopes in the common domain).
So it is fully expected and intended for people to manually adjust
the scope in the auto-generated metadata/idp-metadata.xml file after
installation. Much later, maybe, once they had the chance to read up
on scopes and what it means.
-peter
More information about the users
mailing list