<p>This is a pretty common model with, for example, Google apps marketplace, notably Atlassian OD. To put some flesh on the bones, if you have a shib-protected apache vhost that responds to *.<a href="http://myapp.org">myapp.org</a>, how do you direct requests to <a href="http://cust1.myapp.org">cust1.myapp.org</a> to the correct IdP entityid with the correct target (e.g. <a href="https://myapp.org/Shibboleth/Login?EntityID=https:cust1.org/idp/login&amp;target=https:cust1.myapp.org/lastpage">https://myapp.org/Shibboleth/Login?EntityID=https:cust1.org/idp/login&amp;target=https:cust1.myapp.org/lastpage</a>) at session initiation? Once you get past this step, everything &#39;just works&#39; in my experience. </p>

<p>An aside, Atlassian have a basic discovery service for their customer subdomain login; Google or orphan. Not great, but not hard-coded to a single IdP either.</p>
<p>Best,</p>
<p>Will</p>
<div class="gmail_quote">On Oct 28, 2012 8:33 PM, &quot;Peter Schober&quot; &lt;<a href="mailto:peter.schober@univie.ac.at" target="_blank">peter.schober@univie.ac.at</a>&gt; wrote:<br type="attribution"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">

* Randy Wiemer &lt;<a href="mailto:wiemerr@hotmail.com" target="_blank">wiemerr@hotmail.com</a>&gt; [2012-10-28 04:04]:<br>
&gt; The counter example is Sales Force which uses a feature they call<br>
&gt; “My Domains”, which is a subdomain per customer, to handle the IdP<br>
&gt; discovery process.<br>
<br>
It doesn&#39;t handle IDP discovery. You&#39;ll need to know the specific<br>
entry point into the service from somewhere else (which hardcodes the<br>
IdP, practically), instead of the subject just going to Service A and<br>
selecting where to log in,<br>
-peter<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a></blockquote></div>