Shibboleth service provider supports two entityIds for same ACS endpoints

Peter Schober peter.schober at univie.ac.at
Mon Dec 2 15:34:16 UTC 2024


Alan Buxey via users <users at shibboleth.net> [2024-12-02 15:50 CET]:
> Also, if there are any attributes that are pairwise (eg ePTID or
> SAML2 pairwise-id) then, as the target is based on the entityID and
> that is now a different ID , then the value released will change and
> be different to that before.

Excellent point and only hinted at (IMHO) in the existing "concept"
wiki space (which is not specific to any entity role; worth adding
something about this?):

> The most important attribute an entityID needs to have is
> persistence. The entityID is the public identifier for a deployment
> and is not only used throughout the deployment's own configuration,
> but more importantly will be used throughout all of the other
> deployments that it interoperates with. As such, changing it will have
> ripple effects throughout many systems you don't control, and will
> often take time to propagate (possibly a lot of time).

https://shibboleth.atlassian.net/wiki/spaces/CONCEPT/pages/928645134/EntityNaming

-peter


More information about the users mailing list