SAML Compliance / SSO Issues
Peter Schober
peter.schober at univie.ac.at
Tue Apr 20 10:00:10 UTC 2021
* TJ Peters <tpeters at leepfrog.com> [2021-04-19 22:52]:
> We are working on configuring our Shibboleth SP to work with a college
> who is using Portal Guard as their IdP vendor. We currently have
> one SP entityID. Tied to this, are many ACS urls, used by many
> colleges and universities. However, this Portal Guard client says that
> every ACS must be tied to a unique entityID, in their system.
Not so (as per the SAML spec you quote and what Nate said), but two
more comments:
In case you supported SLO on that SP that is an issue because the
SingleLogoutService element is not an indexed type (the way ACS URLs
are), meaning you can't have multiple Locations for the same Binding
in a single SP. In that sense SLO endpoints are effectively tied to a
unique entityID.
Also, questions about SAML and SAML compliance should go to
saml-dev at lists.oasis-open.org, not the Shibboleth (software) users
mailing list.
-peter
More information about the users
mailing list