<html>
<head>
<style><!--
.hmmessage P
{
margin:0px;
padding:0px
}
body.hmmessage
{
font-size: 12pt;
font-family:Calibri
}
--></style></head>
<body class='hmmessage'><div dir='ltr'>Currently all user sessions are initiated at SP and we do not use discovery service.&nbsp;<div><br><div><br><div><div id="SkyDrivePlaceholder"></div>&gt; From: cantor.2@osu.edu<br>&gt; To: users@shibboleth.net<br>&gt; Subject: Re: Addition of SAML2 support for SP<br>&gt; Date: Thu, 8 Nov 2012 20:17:16 +0000<br>&gt; <br>&gt; On 11/8/12 3:12 PM, "Ian Young" &lt;ian@iay.org.uk&gt; wrote:<br>&gt; &gt;<br>&gt; &gt;Presumably that's true now if the SP has only SAML 1 metadata?  Which is<br>&gt; &gt;to say, it's not making anything worse?<br>&gt; <br>&gt; It depends on error handling and discovery, but yes, in some sense it<br>&gt; might just be changing where the error shows up. But that would be a sign<br>&gt; of a discovery problem in terms of how things are deployed. If you give<br>&gt; users the option to pick an IdP that doesn't actually work for your<br>&gt; system, then of course it will break but that's a fixable issue by<br>&gt; changing discovery.<br>&gt; <br>&gt; -- Scott<br>&gt; <br>&gt; <br>&gt; --<br>&gt; To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br></div></div></div>                                               </div></body>
</html>