I am using IdP version 2.3.6, I have read through wiki  <a href="https://wiki.shibboleth.net/confluence/display/SHIB2/IdPEnableECP">https://wiki.shibboleth.net/confluence/display/SHIB2/IdPEnableECP</a>, and some relevant articles.<div>

<br></div><div>If I understand correctly:</div><div>1. Shib IdP 2.3.6 has ECP enabled by default.</div><div>2. At some point ECP client needs to send AuthnRequest SOAP request to IdP.</div><div><br></div><div>My question is: How does ECP know where to send the AuthnRequest? In the SAML doc I see this part:</div>

<div><br></div><div><div>ECP Determines Identity Provider</div><div>In step 3, the ECP obtains the location of an endpoint at an identity provider for the authentication</div><div>request protocol that supports its preferred binding. The means by which this is accomplished is</div>

<div>implementation-dependent. The ECP MAY use the SAML identity provider discovery profile</div><div>described in Section 4.3.</div><div><br></div><div>So, it is actually implementation-dependent, I want to know how Shib IdP works? I don&#39;t see any information about ECP in the idp-metadata file.</div>

<div><br></div><div><br></div><div>Best,</div>Yaowen<br>
</div>