SP3 multiple vhosts with acs index

Cantor, Scott cantor.2 at osu.edu
Wed Jun 16 13:58:07 UTC 2021

>    Any idea how to configure the acsindex value depending on the vhost that is requested?

There isn't one, I doubt that ever worked reliably because the vhosts themselves are not part of the configuration. Even when every endpoint is spelled out in the configuration with an index, it still can't use them as is because of the vhost problem.

The support of indexes essentially ended almost 15 years ago once it became clear that it couldn't work. A breaking redesign will probably remove the support for it entirely.

I'm going to compile a list of deprecations to add and warn on soon, and this would make that list.

Note that it is a requirement of the standard for an IdP to support by-value. That's why indexes are no longer relevant. SAML is full of places where there are needlessly >1 way to do things and often all but one are dumb, and this was one of them.

-- Scott

