Metadata, examples, best practices?
Jason Gauthier
jgauthier at lastar.com
Wed Nov 27 14:45:41 EST 2013
I hate to respond to my own email before anyone else, but I just discovered that I cannot create a different relaying partying for every virtualhost, because I use a wildcard SSL certificate on some and ADFS does not allow multiple relaying parties with the same signing certificate.
But, I am still wanting to know about the metadata delivery, and how to even add multiple AssertionConsumerService.
Thank you!
-----Original Message-----
From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] On Behalf Of Jason Gauthier
Sent: Wednesday, November 27, 2013 2:33 PM
To: users at shibboleth.net
Subject: Metadata, examples, best practices?
This is probably an elementary question, and I'm okay wit that... so go easy on me.
I have used shib a few times, and achieved what I wanted to achieve. I am now setting up something a little more elaborate and I want to get things done well from the beginning.
For my environment shib is an SP, and ADFS is the IDP. Just to set the imagery properly.
I have set up a new Apache system with shib SP, and have protected an internal site. I did this just to get the baseline.
Ultimately, this system is going to protect, and reverse proxy several internal sites.
In ADFS I could go the route of one relaying party with multiple assertion consumer endpoints, or I could make one for each "virtualhost".
If I make one (maybe that's bad practice) how do I go about adding additional "md:AssertionConsumerService" records to the metadata?
I attempted to do this, and it came out poorly.
Now, on the subject of metadata (and this might be the most important question) " <!-- This is example metadata only. Do *NOT* supply it as is without review, and do *NOT* provide it in real time to your partners.
-->"
What is the preferred method to provide this metadata to ADFS? ( which is my only partner, and it's internal) I have read through the SP documentation, and I just simply do not see (perhaps because it's not right in my face) the best method to provide metadata.
Is that simply copying what is generated automatically and then modifying it for my needs, and then servicing it up as on another URL, or is there any configuration where serving it up from the "generation handler" valid?
Thanks very much!
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list