Thanks a lot Nate,<div><br></div><div>End points nothing but AssertionConsumerService correct, They are present in my metadata which was uploaded to the <a href="http://testshib.org">testshib.org</a> IDP, one more thing if i interchange the places for dev and test then test will work and dev will not works (now <a href="http://dev.mydomain.net">dev.mydomain.net</a> will gets the error message like previous)</div>

<div><br></div><div>Here the exact metadata of <a href="http://Test.Mydomain.net">Test.Mydomain.net</a>.</div><div><br></div><div><div>&lt;md:EntityDescriptor xmlns:md=&quot;urn:oasis:names:tc:SAML:2.0:metadata&quot; ID=&quot;_d27fc6cfbb1c99cb5eb6a848d6b2a385cacb7bf9&quot; entityID=&quot;<a href="https://test.mydomain.net/shibboleth">https://test.mydomain.net/shibboleth</a>&quot;&gt;</div>

<div><br></div><div>  &lt;md:SPSSODescriptor protocolSupportEnumeration=&quot;urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:1.0:protocol&quot;&gt;</div><div>    &lt;md:Extensions&gt;</div>

<div>      &lt;init:RequestInitiator xmlns:init=&quot;urn:oasis:names:tc:SAML:profiles:SSO:request-init&quot; Binding=&quot;urn:oasis:names:tc:SAML:profiles:SSO:request-init&quot; Location=&quot;<a href="http://test.mydomain.net/Shibboleth.sso/Login">http://test.mydomain.net/Shibboleth.sso/Login</a>&quot;/&gt;</div>

<div>    &lt;/md:Extensions&gt;</div><div>    &lt;md:KeyDescriptor&gt;</div><div>      &lt;ds:KeyInfo xmlns:ds=&quot;<a href="http://www.w3.org/2000/09/xmldsig#">http://www.w3.org/2000/09/xmldsig#</a>&quot;&gt;</div><div>

        &lt;ds:KeyName&gt;ths-multitenant.ths.local&lt;/ds:KeyName&gt;</div><div>        &lt;ds:X509Data&gt;</div><div>          &lt;ds:X509SubjectName&gt;CN=ths-multitenant.ths.local&lt;/ds:X509SubjectName&gt;</div><div>

          &lt;ds:X509Certificate&gt; encoded one</div><div>&lt;/ds:X509Certificate&gt;</div><div>        &lt;/ds:X509Data&gt;</div><div>      &lt;/ds:KeyInfo&gt;</div><div>    &lt;/md:KeyDescriptor&gt;</div><div>    &lt;md:ArtifactResolutionService Binding=&quot;urn:oasis:names:tc:SAML:2.0:bindings:SOAP&quot; Location=&quot;<a href="http://test.mydomain.net/Shibboleth.sso/Artifact/SOAP">http://test.mydomain.net/Shibboleth.sso/Artifact/SOAP</a>&quot; index=&quot;0&quot;/&gt;</div>

<div>    &lt;md:SingleLogoutService Binding=&quot;urn:oasis:names:tc:SAML:2.0:bindings:SOAP&quot; Location=&quot;<a href="http://test.mydomain.net/Shibboleth.sso/SLO/SOAP">http://test.mydomain.net/Shibboleth.sso/SLO/SOAP</a>&quot;/&gt;</div>

<div>    &lt;md:SingleLogoutService Binding=&quot;urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect&quot; Location=&quot;<a href="http://test.mydomain.net/Shibboleth.sso/SLO/Redirect">http://test.mydomain.net/Shibboleth.sso/SLO/Redirect</a>&quot;/&gt;</div>

<div>    &lt;md:SingleLogoutService Binding=&quot;urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST&quot; Location=&quot;<a href="http://test.mydomain.net/Shibboleth.sso/SLO/POST">http://test.mydomain.net/Shibboleth.sso/SLO/POST</a>&quot;/&gt;</div>

<div>    &lt;md:SingleLogoutService Binding=&quot;urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact&quot; Location=&quot;<a href="http://test.mydomain.net/Shibboleth.sso/SLO/Artifact">http://test.mydomain.net/Shibboleth.sso/SLO/Artifact</a>&quot;/&gt;</div>

<div>    &lt;md:AssertionConsumerService Binding=&quot;urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST&quot; Location=&quot;<a href="http://test.mydomain.net/Shibboleth.sso/SAML2/POST">http://test.mydomain.net/Shibboleth.sso/SAML2/POST</a>&quot; index=&quot;0&quot;/&gt;</div>

<div>    &lt;md:AssertionConsumerService Binding=&quot;urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign&quot; Location=&quot;<a href="http://test.mydomain.net/Shibboleth.sso/SAML2/POST-SimpleSign">http://test.mydomain.net/Shibboleth.sso/SAML2/POST-SimpleSign</a>&quot; index=&quot;1&quot;/&gt;</div>

<div>    &lt;md:AssertionConsumerService Binding=&quot;urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact&quot; Location=&quot;<a href="http://test.mydomain.net/Shibboleth.sso/SAML2/Artifact">http://test.mydomain.net/Shibboleth.sso/SAML2/Artifact</a>&quot; index=&quot;2&quot;/&gt;</div>

<div>    &lt;md:AssertionConsumerService Binding=&quot;urn:oasis:names:tc:SAML:2.0:bindings:PAOS&quot; Location=&quot;<a href="http://test.mydomain.net/Shibboleth.sso/SAML2/ECP">http://test.mydomain.net/Shibboleth.sso/SAML2/ECP</a>&quot; index=&quot;3&quot;/&gt;</div>

<div>    &lt;md:AssertionConsumerService Binding=&quot;urn:oasis:names:tc:SAML:1.0:profiles:browser-post&quot; Location=&quot;<a href="http://test.mydomain.net/Shibboleth.sso/SAML/POST">http://test.mydomain.net/Shibboleth.sso/SAML/POST</a>&quot; index=&quot;4&quot;/&gt;</div>

<div>    &lt;md:AssertionConsumerService Binding=&quot;urn:oasis:names:tc:SAML:1.0:profiles:artifact-01&quot; Location=&quot;<a href="http://test.mydomain.net/Shibboleth.sso/SAML/Artifact">http://test.mydomain.net/Shibboleth.sso/SAML/Artifact</a>&quot; index=&quot;5&quot;/&gt;</div>

<div>  &lt;/md:SPSSODescriptor&gt;</div><div><br></div><div>&lt;/md:EntityDescriptor&gt;</div></div><div><br></div><div>-Raja</div><div class="gmail_extra"><br><br><div class="gmail_quote">On Thu, Nov 1, 2012 at 4:52 AM, Nate Klingenstein <span dir="ltr">&lt;<a href="mailto:ndk@internet2.edu" target="_blank">ndk@internet2.edu</a>&gt;</span> wrote:<br>

<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div style="word-wrap:break-word"><div>Raja,</div><div><br></div><div>The metadata that you uploaded to TestShib probably doesn&#39;t have endpoints listed for the domain <a href="http://test.mydomain.net" target="_blank">test.mydomain.net</a>.  You&#39;ll need to ensure that there are AssertionConsumerService URL&#39;s for both hosts.</div>

<div><br></div><div><a href="https://wiki.shibboleth.net/confluence/display/SHIB2/MetadataForSP" target="_blank">https://wiki.shibboleth.net/confluence/display/SHIB2/MetadataForSP</a></div><div><br></div><div>Thanks,</div>

<div>Nate.</div><div><div class="h5"><div><br><div><div>On 31 Oct 2012, at 23:08, &quot;Raz&#39;s&quot; &lt;<a href="mailto:gajula.rajashekhar@gmail.com" target="_blank">gajula.rajashekhar@gmail.com</a>&gt; wrote:</div><br>

<blockquote type="cite">Hi Nate,<br><div class="gmail_extra"><div><br></div><div>When i configured SP as follows </div><div><br></div><div><div>            &lt;Site id=&quot;1&quot; name=&quot;<a href="http://sp.mydomain.net/" target="_blank">sp.mydomain.net</a>&quot;&gt;</div>



<div>            <span style="white-space:pre-wrap">        </span>&lt;Alias&gt;<a href="http://dev.mydomain.net/" target="_blank">dev.mydomain.net</a>&lt;/Alias&gt;</div><div>            <span style="white-space:pre-wrap">        </span>&lt;Alias&gt;<a href="http://test.mydomain.net/" target="_blank">test.mydomain.net</a>&lt;/Alias&gt;</div>



</div><div>            &lt;/Site&gt;</div><div><br></div><div><div>    &lt;RequestMapper type=&quot;Native&quot;&gt;</div><div>        &lt;RequestMap applicationId=&quot;default&quot;&gt;</div><div>            &lt;Host name=&quot;<a href="http://dev.mydomain.net/" target="_blank">dev.mydomain.net</a>&quot;&gt;<br>



</div><div>                &lt;Path name=&quot;protected&quot; authType=&quot;shibboleth&quot; requireSession=&quot;true&quot;/&gt;</div><div>            &lt;/Host&gt;</div><div>            &lt;Host name=&quot;<a href="http://test.mydomain.net/" target="_blank">test.mydomain.net</a>&quot; entityID=&quot;<a href="https://idp.testshib.org/idp/shibboleth" target="_blank">https://idp.testshib.org/idp/shibboleth</a>&quot;&gt;</div>



<div>                &lt;Path name=&quot;protected&quot; authType=&quot;shibboleth&quot; requireSession=&quot;true&quot;/&gt;</div><div>            &lt;/Host&gt;</div><div>        &lt;/RequestMap&gt;<br></div><div>    &lt;/RequestMapper&gt;</div>



</div><div><br></div><div><div>        &lt;ApplicationDefaults entityID=&quot;<a href="https://dev.mydomain.net/shibboleth" target="_blank">https://dev.mydomain.net/shibboleth</a>&quot; REMOTE_USER=&quot;eppn&quot;&gt;</div>

<div><br></div>

<div>        &lt;Sessions lifetime=&quot;28800&quot; timeout=&quot;3600&quot; checkAddress=&quot;true&quot; consistentAddress=&quot;true&quot; relayState=&quot;ss:mem&quot; handlerSSL=&quot;false&quot;&gt;<br></div><div>


            &lt;SSO entityID=&quot;<a href="https://idp.testshib.org/idp/shibboleth" target="_blank">https://idp.testshib.org/idp/shibboleth</a>&quot;&gt;<br>
</div><div>                SAML2 SAML1</div><div>            &lt;/SSO&gt;</div><div><br></div><div>            &lt;Logout&gt;SAML2 Local&lt;/Logout&gt;<br></div><div><br></div><div>            &lt;Handler type=&quot;MetadataGenerator&quot; Location=&quot;/Metadata&quot; signing=&quot;false&quot;/&gt;<br>



</div><div>            &lt;Handler type=&quot;Status&quot; Location=&quot;/Status&quot; acl=&quot;127.0.0.1&quot;/&gt;<br></div><div>            &lt;Handler type=&quot;Session&quot; Location=&quot;/Session&quot; showAttributeValues=&quot;true&quot;/&gt;<br>



</div><div>            &lt;Handler type=&quot;DiscoveryFeed&quot; Location=&quot;/DiscoFeed&quot;/&gt;<br></div><div><br></div><div>        &lt;/Sessions&gt;</div><div><br></div><div>        &lt;Errors supportContact=&quot;root@localhost&quot; logoLocation=&quot;/shibboleth-sp/logo.jpg&quot; styleSheet=&quot;/shibboleth-sp/main.css&quot;/&gt;</div>



<div><br></div><div>        &lt;MetadataProvider type=&quot;XML&quot; uri=&quot;<a href="http://www.testshib.org/metadata/testshib-providers.xml" target="_blank">http://www.testshib.org/metadata/testshib-providers.xml</a>&quot;<br>

</div>

<div>             backingFilePath=&quot;testshib-two-idp-metadata.xml&quot; reloadInterval=&quot;180000&quot; /&gt;</div><div><br></div><div>        &lt;AttributeExtractor type=&quot;XML&quot; validate=&quot;true&quot; path=&quot;attribute-map.xml&quot;/&gt;<br>



</div><div>        &lt;AttributeResolver type=&quot;Query&quot; subjectMatch=&quot;true&quot;/&gt;</div><div>        &lt;AttributeFilter type=&quot;XML&quot; validate=&quot;true&quot; path=&quot;attribute-policy.xml&quot;/&gt;</div>



<div><br></div><div>        &lt;CredentialResolver type=&quot;File&quot; key=&quot;sp-key.pem&quot; certificate=&quot;sp-cert.pem&quot;/&gt;<br></div></div><div><div><br></div><div>        &lt;/ApplicationDefaults&gt;    </div>



</div><div><br></div><div>then i&#39;m getting the error like <strong style="font-family:&#39;Times New Roman&#39;;font-size:medium">Error Message: No peer endpoint available to which to send SAML response</strong><br>

</div><div><font face="Times New Roman" size="3">while access the <a href="http://test.mydomain.net/" target="_blank">test.mydomain.net</a> but it&#39;s working fine with <a href="http://dev.mydomain.net/" target="_blank">dev.mydomain.net</a></font></div>



<div><font face="Times New Roman" size="3"><br></font></div><div><font face="Times New Roman" size="3">Here <a href="http://test.mydomain.net/" target="_blank">test.mydomain.net</a> IDP &amp; sessions, handlers etc different from the dev.</font></div>



<div><font face="Times New Roman" size="3"><br></font></div><div><font face="Times New Roman" size="3">-Raja</font></div><div><font face="Times New Roman" size="3"><br></font></div>

On Wed, Oct 31, 2012 at 12:30 AM, Cantor, Scott <span dir="ltr">&lt;<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>&gt;</span> wrote:<br><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);border-left-style:solid;padding-left:1ex">



<div>&gt;<br>
&gt;Please help me out in the process of SAML SP implementation for sub<br>
&gt;domains. This implementation little bit tricky here single application<br>
&gt;providing the solutions or our clients using the sub domains so each sub<br>
&gt;domain indicates the individual client and<br>
&gt; also each client had the his own idp and sp but we want to integrate<br>
&gt;their idp into our sp at the same it has to redirect the request to<br>
&gt;respected sub domains (clients) idp. Here Session of each and every sub<br>
&gt;domain (client) should be vary based on the sub<br>
&gt; domain(client) idp.<br>
<br>
</div>I answered this in the original thread you raised it in. If you want to<br>
specify the IdP based on the vhost, you add an entityID property naming<br>
the IdP in the RequestMap in a &lt;Host&gt; element for the given vhost. That&#39;s<br>
it. You don&#39;t need overrides.<br>
<br></blockquote><div><br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);border-left-style:solid;padding-left:1ex">
If you need to add restrictions to limit which IdP&#39;s users are able to<br>
access the vhosts, then there are various ways to achieve that, or it can<br>
be done entirely inside the application. Again, you don&#39;t need overrides<br>
for that.<br>
<span><font color="#888888"><br>
-- Scott<br>
</font></span><div><div><br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br></div>
--<br>To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a></blockquote></div><br></div></div></div></div><br>--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br></blockquote></div><br></div>