FW: 2 Shibboleth SP’s with 2 different entity IDs but same AssertionConsumerService(ACS) URL
Peter Schober
peter.schober at univie.ac.at
Wed Mar 5 11:27:18 UTC 2025
Muthukumar Manohar, Emily (ELS-CON) via users <users at shibboleth.net> [2025-03-05 11:34 CET]:
> We have a business requirement where we need to have 2 Shibboleth
> SP’s with 2 different entity IDs but same
> AssertionConsumerService(ACS) URL and both SPs will be running on
> the same server.
A different entityID means it's a completely different SP. One of
those 2 SPs must have been established earlier, so why/how could it be
a "business requirement" for the one that came later to have a
protocol endpoint that's in use by another SP?
(Business requirements don't deal with ACS URLs, in my experience.)
If the purpose of this exercise is to change the entityID without
disrupting established deployments (that may know the ACS URL) then
don't bother: Changing the entityID always means breaking things and
having to deal with it. You might as well have different ACS URLs
then.
-peter
More information about the users
mailing list