<div>Scott,</div><div> </div><div>Thanks for the info. This is all confusing for me so I'm sure my use of terms or how I understand them may be incorrect.</div><div>I'm used to going to <a href="https://somesite/Shibboleth.sso/Metadata">https://somesite/Shibboleth.sso/Metadata</a> in order to generate the metadata for each client site for them to install on their IdP.</div>
<div>My confusion was that there is nothing that tells that to get things remotely. Or I was just doing it wrong.</div><div> </div><div>And, yes, I am looking for multiple metadata sources - InCommon and others. What I would also like to do is the following:</div>
<div> </div><div>1. Have both <a href="http://site1.somewhere.com">site1.somewhere.com</a> and <a href="http://site2.somewhere.com">site2.somewhere.com</a> use a common SP - <a href="http://sp.somewhere.com">sp.somewhere.com</a>. So, in each site, they would have a login link that points to <a href="http://sp.somewhere.com/secure">sp.somewhere.com/secure</a>. This should bounce the user to the appropriate login for their site. Do I have that logic right?</div>
<div> </div><div>Thanks,</div><div>Jason<br></div><div class="gmail_quote">On Thu, Mar 15, 2012 at 4:56 PM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>></span> wrote:<br><blockquote style="margin:0px 0px 0px 0.8ex;padding-left:1ex;border-left-color:rgb(204,204,204);border-left-width:1px;border-left-style:solid" class="gmail_quote">
> I am wanting to convert my existing Shibboleth SP installation from a native<br>
> (using local SP metadata file AND connecting to IDPs using local metadata<br>
> files) to an InCommon/Shibboleth SP installation (with my SP metadata being<br>
> pulled from InCommon).<br>
<br>
Your terminology is confusing here, but to start with, the SP doesn't use "SP metadata", only IdP metadata. So if you're saying you want the SP to be provisioning its IdPs from InCommon instead of a local file, I get it.<br>
<br>
> My biggest hurdle is I don't see where in the<br>
> shibboleth2.xml file I need to specify that my SP metadata is to now be<br>
> supplied remotely.<br>
<br>
Again, you don't use SP metadata. You specify IdP metadata remotely by using the XML provider with a url or uri attribute instead of a file or path attribute, and the various other trust related filtering you need.<br>
<br>
> I have seen this line mentioned a few times in other posts:<br>
<br>
InCommon has documentation that outlines how to provision the SP with their metadata, yes.<br>
<br>
> However, I was under the impression that this XML attribute was to tell<br>
> Shibboleth how to interact with the IDPs. Do I have that wrong? Does it<br>
> control both??<br>
<br>
Both what?<br>
<br>
> 1. Use my new InCommon SP metadata for all my connections<br>
> 2. Use InCommon IDPs for those that are in InCommon<br>
> 3. Use local IDP metadata files for those not in InCommon<br>
> 4. All this using one Shibboleth installation.<br>
<br>
That just means you need multiple metadata sources, InCommon and others.<br>
<br>
I think you're under the impression that the SP being "in InCommon" has some impact on its configuration as an SP, but it really doesn't.<br>
<br>
-- Scott<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div><br><br clear="all"><br>-- <br><div> </div>
<div>…………………………<br>Jason Johnson<br>Terra Dotta, LLC<br>501 W. Franklin Street, Suite 105<br>Chapel Hill, NC 27516<br>Phone/Fax: 877-DOTTA-77 (877-368-8277) x111<br><a href="http://terradotta.com/" target="_blank">http://TerraDotta.com</a></div>
<p><a href="https://university.terradotta.com/index.cfm?FuseAction=Abroad.ViewLink&Parent_ID=0&Link_ID=7AD7CAC2-E525-4C47-3EA59E2DD4EBF068" target="_blank"><strong>Register for Terra Dotta University in Charlotte, NC: April 18-20, 2012</strong></a></p>
<br>