<META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=us-ascii">
<meta name=Generator content="Microsoft Word 11 (filtered medium)">
<!--[if !mso]>
<style>
v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style>
<![endif]-->






<div class=Section1>

<p class=MsoNormal><font size=2 color=navy face=Arial><span style='font-size:
10.0pt;font-family:Arial;color:navy'>Thank you.<o:p></o:p></span></font></p>

<p class=MsoNormal><font size=3 face="Times New Roman"><span style='font-size:
12.0pt'>&nbsp;</span></font></p>

<p class=MsoNormal style='margin-bottom:12.0pt'><font size=3
face="Times New Roman"><span style='font-size:12.0pt'>On 8/20/12 6:49 PM,
&quot;csross&quot; &lt;<a href="/user/SendEmail.jtp?type=node&amp;node=7581404&amp;i=0"
target="_top" link="external" rel="nofollow">[hidden email]</a>&gt; wrote: <br>
<br>
&gt;I have multiple v2.4.3 SPs and each defined in an ApplicationOverride and <br>
&gt;vhost and I am able to bring up metadata for each SP. &nbsp;The
documentation <br>
&gt;indicates this below but it doesn't say what will be wrong or missing. <br>
<br>
Lots of advanced features, policy flags, keys during credential rollovers <br>
(you CANNOT safely migrate keys using only generated metadata), contact <br>
information, new extensions. Many, many things. None of that has anything <br>
to do with overrides particularly. <br>
<br>
The point about overrides is that by definition a request to a handler is <br>
talking to one application, period, and so by definition you can't be <br>
incorporating input coming from the others, whatever that input is. There <br>
is no way to answer the specific question unless the purpose of the <br>
overrides is made clear. <br>
<br>
&gt;One of the SPs was originally the only one (v2.2) so it was defined as the <br>
&gt;ApplicationDefault and the metadata &nbsp;looks very similar. &nbsp;After
upgrading <br>
&gt;and switching to ApplicationOverrides, I generated the metadata in the <br>
&gt;same <br>
&gt;way (<a href="https://site.site.com/Shibboleth.sso/Metadata" target="_top" link="external" rel="nofollow">https://site.site.com/Shibboleth.sso/Metadata</a>) and sent it to
the IDP <br>
&gt;admin. &nbsp;The IDP is shibboleth and the admin said it looked fine.
&nbsp;The site <br>
&gt;is working too. <br>
<br>
That's usually a sign the override isn't/wasn't needed. <br>
<br>
&gt;NOTE: &nbsp;In the metadata when 1 SP as ApplicationDefault was used, the
X509 <br>
&gt;certificate is different, there is an extra certificate md:KeyDescriptor <br>
&gt;use=&quot;signing&quot; and there are these lines <br>
<br>
That's not because of the overrides, that's a question of configuration <br>
differences and version differences. You do not need and should not <br>
advertise NameID management endpoints. If you don't know what they do, you <br>
don't have them. That goes for essentially everything in the metadata. <br>
<br>
As a starting point, you should be able to understand the differences. If <br>
you can't do that, I would strongly urge that you read the specification. <br>
There's no other advice I can give but to do that. There's no book to <br>
read, or I would give you a link to it. <br>
<br>
-- Scott <br>
<br>
-- <br>
To unsubscribe from this list send an email to <a
href="/user/SendEmail.jtp?type=node&amp;node=7581404&amp;i=1" target="_top" link="external" rel="nofollow">[hidden email]</a> <br>
<br>
<o:p></o:p></span></font></p>

<div class=MsoNormal align=center style='text-align:center'><font size=3
face="Times New Roman"><span style='font-size:12.0pt'>

<hr size=1 width="100%" noshade color="#cccccc" align=center>

</span></font></div>

<div>

<div>

<p class=MsoNormal><b><font size=1 color="#444444" face=Tahoma><span
style='font-size:9.0pt;font-family:Tahoma;color:#444444;font-weight:bold'>If
you reply to this email, your message will be added to the discussion below:<o:p></o:p></span></font></b></p>

</div>

<p class=MsoNormal><font size=1 color="#444444" face=Tahoma><span
style='font-size:9.0pt;font-family:Tahoma;color:#444444'><a
href="http://shibboleth.1660669.n2.nabble.com/documentation-regarding-ApplicationOverrides-and-metadata-generator-tp7581403p7581404.html" target="_top" rel="nofollow" link="external">http://shibboleth.1660669.n2.nabble.com/documentation-regarding-ApplicationOverrides-and-metadata-generator-tp7581403p7581404.html</a>
<o:p></o:p></span></font></p>

</div>

<div style='margin-top:4.8pt'>

<p class=MsoNormal style='line-height:18.0pt'><font size=1 color="#666666"
face=Tahoma><span style='font-size:8.5pt;font-family:Tahoma;color:#666666'>To
unsubscribe from documentation regarding ApplicationOverrides and metadata
generator, <a
href="" target="_top" rel="nofollow" link="external">click
here</a>.<br>
<a
href="http://shibboleth.1660669.n2.nabble.com/template/NamlServlet.jtp?macro=macro_viewer&amp;id=instant_html%21nabble%3Aemail.naml&amp;base=nabble.naml.namespaces.BasicNamespace-nabble.view.web.template.NabbleNamespace-nabble.view.web.template.NodeNamespace&amp;breadcrumbs=notify_subscribers%21nabble%3Aemail.naml-instant_emails%21nabble%3Aemail.naml-send_instant_email%21nabble%3Aemail.naml" target="_top" rel="nofollow" link="external"><font
size=1 face="Times New Roman"><span style='font-size:7.0pt;font-family:"Times New Roman"'>NAML</span></font></a>
<o:p></o:p></span></font></p>

</div>

</div>






        
        
        
<br/><hr align="left" width="300" />
View this message in context: <a href="http://shibboleth.1660669.n2.nabble.com/documentation-regarding-ApplicationOverrides-and-metadata-generator-tp7581403p7581406.html">RE: documentation regarding ApplicationOverrides and metadata generator</a><br/>
Sent from the <a href="http://shibboleth.1660669.n2.nabble.com/Shibboleth-Users-f1660767.html">Shibboleth - Users mailing list archive</a> at Nabble.com.<br/>