Metadata configuration for multiple SPs

Klingenstein, Nate nklingenstein at calstate.edu
Mon Nov 14 03:42:36 EST 2016


Alex,

A bundle of entities is the same, no matter what kinds of entities are in the bag.  You just need the right bag, and if you're not signing it or distributing it, there's not much to it.

I would try using:

http://testshib.org/metadata/testshib-providers.xml

as an annotated template, and you can just rip out the IdP entry and replace it with the other SP's entry.  Make sure you pick a unique name for your EntitiesDescriptor.  There Can Be Only One TestShib.

If you would like to learn more, oh so much more,

https://wiki.shibboleth.net/confluence/display/CONCEPT/MetadataCorrectness

Back to bed,
Nate.

On Nov 14, 2016, at 12:31 AM, Alexander Ivanov <alex at calmforce.com<mailto:alex at calmforce.com>> wrote:

Hello,

We have two separate working configurations for two applications to authenticate against our Shibboleth IdP, and would now like to configure our IdP to work simultaneously for both.

I found these two posts relevant:
http://shibboleth.net/pipermail/users/2012-May/004075.html
http://shibboleth.net/pipermail/users/2012-September/006042.html

As I've gathered from the aforementioned posts, it should be possible to consolidate our two separate metadata definitions into one sp-metadata.xml file.  However, I've had no luck thus far in actually making this work.  I must have the wrong syntax- I've used a simple "EntitiesDescriptor" tag to surround the two separate EntityDescriptor definitions.

Please advise on the correct syntax for the joint SP Metadata file.

Thanks a lot,
Alex
<sp-metadata.xml><sp-metadata.drupal.xml><sp-metadata.dv.xml>--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net<mailto:users-unsubscribe at shibboleth.net>

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20161114/616c0c19/attachment.html>


More information about the users mailing list