Two endpoints, same entityID, different attribute filter?

Cantor, Scott cantor.2 at osu.edu
Tue Feb 7 08:53:38 EST 2017


> By default in the IDP, I think the Audience URL and the SPNameQualifier
> are the entityID, and the response is the AssertionConsumerService
> Location.  I'd like the response URL to trigger a specific set of
> attribute release rules, in case we need to serve two different
> populations for Marketo (it isn't campus-wide).

You can do it with a script or plugin, but I really wouldn't.

> If I make two entityID's, one has to not be http://saml.marketo.com/sp,
> then the Subject and Conditions stanzas of the response have the new
> entityID for the Audience and SPNameQualifier, which seems to cause a
> problem.

You can also control all of that if you really had to, but again, I wouldn't.

-- Scott



More information about the users mailing list