<div>Scott,</div><div> </div><div>Thanks for the info. This is all confusing for me so I&#39;m sure my use of terms or how I understand them may be incorrect.</div><div>I&#39;m used to going to <a href="https://somesite/Shibboleth.sso/Metadata">https://somesite/Shibboleth.sso/Metadata</a> in order to generate the metadata for each client site for them to install on their IdP.</div>
<div>My confusion was that there is nothing that tells that to get things remotely.  Or I was just doing it wrong.</div><div> </div><div>And, yes, I am looking for multiple metadata sources - InCommon and others.  What I would also like to do is the following:</div>
<div> </div><div>1.  Have both <a href="http://site1.somewhere.com">site1.somewhere.com</a> and <a href="http://site2.somewhere.com">site2.somewhere.com</a> use a common SP - <a href="http://sp.somewhere.com">sp.somewhere.com</a>.  So, in each site, they would have a login link that points to <a href="http://sp.somewhere.com/secure">sp.somewhere.com/secure</a>.  This should bounce the user to the appropriate login for their site.  Do I have that logic right?</div>
<div> </div><div>Thanks,</div><div>Jason<br></div><div class="gmail_quote">On Thu, Mar 15, 2012 at 4:56 PM, Cantor, Scott <span dir="ltr">&lt;<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>&gt;</span> wrote:<br><blockquote style="margin:0px 0px 0px 0.8ex;padding-left:1ex;border-left-color:rgb(204,204,204);border-left-width:1px;border-left-style:solid" class="gmail_quote">
&gt; I am wanting to convert my existing Shibboleth SP installation from a native<br>
&gt; (using local SP metadata file AND connecting to IDPs using local metadata<br>
&gt; files) to an InCommon/Shibboleth SP installation (with my SP metadata being<br>
&gt; pulled from InCommon).<br>
<br>
Your terminology is confusing here, but to start with, the SP doesn&#39;t use &quot;SP metadata&quot;, only IdP metadata. So if you&#39;re saying you want the SP to be provisioning its IdPs from InCommon instead of a local file, I get it.<br>

<br>
&gt;  My biggest hurdle is I don&#39;t see where in the<br>
&gt; shibboleth2.xml file I need to specify that my SP metadata is to now be<br>
&gt; supplied remotely.<br>
<br>
Again, you don&#39;t use SP metadata. You specify IdP metadata remotely by using the XML provider with a url or uri attribute instead of a file or path attribute, and the various other trust related filtering you need.<br>

<br>
&gt;  I have seen this line mentioned a few times in other posts:<br>
<br>
InCommon has documentation that outlines how to provision the SP with their metadata, yes.<br>
<br>
&gt; However, I was under the impression that this XML attribute was to tell<br>
&gt; Shibboleth how to interact with the IDPs.  Do I have that wrong?  Does it<br>
&gt; control both??<br>
<br>
Both what?<br>
<br>
&gt; 1.  Use my new InCommon SP metadata for all my connections<br>
&gt; 2.  Use InCommon IDPs for those that are in InCommon<br>
&gt; 3.  Use local IDP metadata files for those not in InCommon<br>
&gt; 4.  All this using one Shibboleth installation.<br>
<br>
That just means you need multiple metadata sources, InCommon and others.<br>
<br>
I think you&#39;re under the impression that the SP being &quot;in InCommon&quot; has some impact on its configuration as an SP, but it really doesn&#39;t.<br>
<br>
-- Scott<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div><br><br clear="all"><br>-- <br><div> </div>
<div>…………………………<br>Jason Johnson<br>Terra Dotta, LLC<br>501 W. Franklin Street, Suite 105<br>Chapel Hill, NC 27516<br>Phone/Fax: 877-DOTTA-77 (877-368-8277) x111<br><a href="http://terradotta.com/" target="_blank">http://TerraDotta.com</a></div>

<p><a href="https://university.terradotta.com/index.cfm?FuseAction=Abroad.ViewLink&amp;Parent_ID=0&amp;Link_ID=7AD7CAC2-E525-4C47-3EA59E2DD4EBF068" target="_blank"><strong>Register for Terra Dotta University in Charlotte, NC: April 18-20, 2012</strong></a></p>
<br>