Multiple entityIDs with the same metadata

Michael Dahlberg olgamirth at gmail.com
Thu Jul 23 15:20:29 EDT 2015


> > The metadata that I was given to add to the IdP only lists the entityId
> and endpoints as foo.bucknell.edu.  Can I modify the metadata so that IdP
> will consider both foo and bar as valid endpoints and I won't receive the
> error message:
> >
> > SAML 2 SSO profile is not configured for relying party
> https://bar.bucknell.edu/shibboleth
>
> Endpoints, yes.  entityID, no.  Changing an entityID is really fun and
> exciting, so if you can avoid that, I would.  Basically, add
> bar.bucknell.edu endpoints alongside the foo.bucknell.edu endpoints to
> your https://foo.bucknell.edu/shibboleth entityID.
>


Ok, I think that's what I tried.  By replicating the
AssertionConsumerService binding tags in the metadata for foo, I thought I
was adding the endpoint bar to the metadata.  It didn't work; same error.

I then tried adding the tag skipEndpointValidationWhenSigned="true" to the
profile configuration for the IdP of the relying-party file.  This also did
not change the error message or the result.

So, I guess my question then is, other then replicating the
AssertionConsumerService binding tags and incrementing the index values,
what else do I need to do to add an endpoint?

Thanks,
Mike
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20150723/e5f35d7e/attachment-0001.html>


More information about the users mailing list