Education vendor SSO configuration requires separate IDP entityIDs for each SP!
Florian Lengyel
Florian.Lengyel at cuny.edu
Wed Dec 21 22:25:45 UTC 2022
Thank you--this is exactly as I expected.
Florian
PS. I don't think you failed at all. On the contrary.
-----Original Message-----
From: Cantor, Scott <cantor.2 at osu.edu>
Sent: Wednesday, December 21, 2022 4:37 PM
To: Shib Users <users at shibboleth.net>
Cc: Florian Lengyel <Florian.Lengyel at cuny.edu>
Subject: Re: Education vendor SSO configuration requires separate IDP entityIDs for each SP!
***ATTENTION: This email came from an external source. Do not open attachments or click on links from unknown senders or unexpected emails.***
> Am I correct that this constraint on IDP and SP entityIDs is nonstandard?
It's not something a standard covers, it's just common sense (to an implementer) that it's a bad idea. The whole individual tenant concept to begin with is not how SAML was meant to be used. We had to trust implementers not to do things that would make life hard for deployers, who shouldn't have to worry about that sort of thing. We failed miserably in that assumption.
> is there a way to generate separate metadata for the same IDP with
> different entityIDs?
Metadata is not generated, it has to come from a third party to be useful to begin with. Self-asserted metadata is worthless and actively harmful.
-- Scott
More information about the users
mailing list