<html><head>
<meta http-equiv="Content-Type" content="text/html; charset=Windows-1252"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; "><div style="color: rgb(0, 0, 0); font-family: Calibri, sans-serif; font-size: 14px; ">Hi all,</div><div style="color: rgb(0, 0, 0); font-family: Calibri, sans-serif; font-size: 14px; "><br></div><div style="color: rgb(0, 0, 0); font-family: Calibri, sans-serif; font-size: 14px; ">Checked out the archives and poked around the shib wiki and to me it looks like an SP that belongs to more than one federation should use the Chaining MetadataProvider configuration[1] to have both federations metadata available to the SP for evaluation.</div><div style="color: rgb(0, 0, 0); font-family: Calibri, sans-serif; font-size: 14px; "><br></div><div style="color: rgb(0, 0, 0); font-family: Calibri, sans-serif; font-size: 14px; ">The question I have is: </div><div style="color: rgb(0, 0, 0); font-family: Calibri, sans-serif; font-size: 14px; ">Can the SP be present with the same entityID in two (or more) metadata files from different federations provided the entityID record contents are identical and used in the identical fashion?</div><div style="color: rgb(0, 0, 0); font-family: Calibri, sans-serif; font-size: 14px; "><br></div><div style="color: rgb(0, 0, 0); font-family: Calibri, sans-serif; font-size: 14px; ">I would like the answer to be 'yes', but I'm leaning toward it being 'no' due to these comments, which are a bit difficult to unwind the meaning:</div><div style="color: rgb(0, 0, 0); font-family: Calibri, sans-serif; font-size: 14px; "><br></div><div style="color: rgb(0, 0, 0); font-family: Calibri, sans-serif; font-size: 14px; ">"<span class="Apple-style-span" style="color: rgb(51, 51, 51); font-size: 13px; line-height: 17px; background-color: rgb(255, 255, 221); font-family: Helvetica, Arial, sans-serif; ">While there is some limited capability for controlling the handling of duplicate entities, it is explicitly</span><span class="Apple-style-span" style="color: rgb(51, 51, 51); font-size: 13px; line-height: 17px; background-color: rgb(255, 255, 221); font-family: Helvetica, Arial, sans-serif; "> </span><span class="Apple-style-span" style="color: rgb(51, 51, 51); font-size: 13px; line-height: 17px; background-color: rgb(255, 255, 221); font-family: Helvetica, Arial, sans-serif; "><b>NOT</b></span><span class="Apple-style-span" style="color: rgb(51, 51, 51); font-size: 13px; line-height: 17px; background-color: rgb(255, 255, 221); font-family: Helvetica, Arial, sans-serif; "> </span><span class="Apple-style-span" style="color: rgb(51, 51, 51); font-size: 13px; line-height: 17px; background-color: rgb(255, 255, 221); font-family: Helvetica, Arial, sans-serif; ">supported for a single</span><span class="Apple-style-span" style="color: rgb(51, 51, 51); font-size: 13px; line-height: 17px; background-color: rgb(255, 255, 221); font-family: Helvetica, Arial, sans-serif; "> </span><span class="Apple-style-span" style="color: rgb(51, 51, 51); font-size: 13px; line-height: 17px; background-color: rgb(255, 255, 221); font-family: Helvetica, Arial, sans-serif; "><tt>entityID</tt></span><span class="Apple-style-span" style="color: rgb(51, 51, 51); font-size: 13px; line-height: 17px; background-color: rgb(255, 255, 221); font-family: Helvetica, Arial, sans-serif; "> </span><span class="Apple-style-span" style="color: rgb(51, 51, 51); font-size: 13px; line-height: 17px; background-color: rgb(255, 255, 221); font-family: Helvetica, Arial, sans-serif; ">to appear more than once with the same valid role, and the software will</span><span class="Apple-style-span" style="color: rgb(51, 51, 51); font-size: 13px; line-height: 17px; background-color: rgb(255, 255, 221); font-family: Helvetica, Arial, sans-serif; "> </span><span class="Apple-style-span" style="color: rgb(51, 51, 51); font-size: 13px; line-height: 17px; background-color: rgb(255, 255, 221); font-family: Helvetica, Arial, sans-serif; "><b>NOT</b></span><span class="Apple-style-span" style="color: rgb(51, 51, 51); font-size: 13px; line-height: 17px; background-color: rgb(255, 255, 221); font-family: Helvetica, Arial, sans-serif; "> </span><span class="Apple-style-span" style="color: rgb(51, 51, 51); font-size: 13px; line-height: 17px; background-color: rgb(255, 255, 221); font-family: Helvetica, Arial, sans-serif; ">behave predictably in such a case. In other words, if the same entity supports a given role, its metadata</span><span class="Apple-style-span" style="color: rgb(51, 51, 51); font-size: 13px; line-height: 17px; background-color: rgb(255, 255, 221); font-family: Helvetica, Arial, sans-serif; "> </span><span class="Apple-style-span" style="color: rgb(51, 51, 51); font-size: 13px; line-height: 17px; background-color: rgb(255, 255, 221); font-family: Helvetica, Arial, sans-serif; "><b>MUST</b></span><span class="Apple-style-span" style="color: rgb(51, 51, 51); font-size: 13px; line-height: 17px; background-color: rgb(255, 255, 221); font-family: Helvetica, Arial, sans-serif; "> </span><span class="Apple-style-span" style="color: rgb(51, 51, 51); font-size: 13px; line-height: 17px; background-color: rgb(255, 255, 221); font-family: Helvetica, Arial, sans-serif; ">be identical in all chained sources."</span></div><div style="color: rgb(0, 0, 0); font-family: Calibri, sans-serif; font-size: 14px; "><br></div><div style="color: rgb(0, 0, 0); font-family: Calibri, sans-serif; font-size: 14px; ">Can someone chime in on what an SP provider should do with their metadata to be included in multiple federations and if the Chaining Metadataprovider is not the right way, what is the right way?</div><div style="color: rgb(0, 0, 0); font-family: Calibri, sans-serif; font-size: 14px; "><br></div><div style="color: rgb(0, 0, 0); font-family: Calibri, sans-serif; font-size: 14px; ">Should it be a different entityID per federation metadata file?</div><div style="color: rgb(0, 0, 0); font-family: Calibri, sans-serif; font-size: 14px; ">Can it be the same entityID for all federation metadata files?</div><div style="color: rgb(0, 0, 0); font-family: Calibri, sans-serif; font-size: 14px; "><br></div><div style="color: rgb(0, 0, 0); font-family: Calibri, sans-serif; font-size: 14px; ">It may be useful to include these items in the documentation and if it is, just let me know what to look for…</div><div style="color: rgb(0, 0, 0); font-family: Calibri, sans-serif; font-size: 14px; "><br></div><div style="color: rgb(0, 0, 0); font-family: Calibri, sans-serif; font-size: 14px; ">Thanks!</div><div style="color: rgb(0, 0, 0); font-family: Calibri, sans-serif; font-size: 14px; "><br></div><div style="color: rgb(0, 0, 0); font-family: Calibri, sans-serif; font-size: 14px; ">Chris.</div><div style="color: rgb(0, 0, 0); font-family: Calibri, sans-serif; font-size: 14px; "><br></div><div style="color: rgb(0, 0, 0); font-family: Calibri, sans-serif; font-size: 14px; ">[1] <a href="https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPMetadataProvider">https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPMetadataProvider</a></div></body></html>