Use Shibboleth installation for two SPs (with different entityID)
Nate Klingenstein
ndk at internet2.edu
Wed Feb 19 15:23:15 EST 2014
Helma,
If you need to use two different SP entityID's in one installation of the Shibboleth SP, then yes, you will need to use an ApplicationOverride. Good luck. See first "valid" reason in the docs.
https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPApplicationOverride
Thanks,
Nate.
On Feb 19, 2014, at 1:14 PM, "Maassen, Helma" <helma.maassen at atos.net>
wrote:
Hi,
We’re trying to solve a problem using Shibboleth SP.
We have two IDPs to connect to, both with their own (=different) entityID, metdata, signing algorithm, session initiator, AuthnRequest (for example authnContextClassRef PasswordProtected or other).
For now we also have to register at the two IDPs with two different entityIDs for the SP. (I understand from Scott that is not very wise!, but I’m not able to change that in the near future :()
The certificate and key from our SP can be reused for “both” SPs.
But with those given parameters, what seems to be the best way to go to solve this problem?
Do we need to use the ApplicationOverride? Or is it possible to do it with RelyingParty(s), combined with two SessionInitiators?
Best Regards,
Helma.
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net<mailto:users-unsubscribe at shibboleth.net>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20140219/d05e572e/attachment.html
More information about the users
mailing list