<html>
<head>
<style><!--
.hmmessage P
{
margin:0px;
padding:0px
}
body.hmmessage
{
font-size: 12pt;
font-family:Calibri
}
--></style></head>
<body class='hmmessage'><div dir='ltr'>Currently all user sessions are initiated at SP and we do not use discovery service. <div><br><div><br><div><div id="SkyDrivePlaceholder"></div>> From: cantor.2@osu.edu<br>> To: users@shibboleth.net<br>> Subject: Re: Addition of SAML2 support for SP<br>> Date: Thu, 8 Nov 2012 20:17:16 +0000<br>> <br>> On 11/8/12 3:12 PM, "Ian Young" <ian@iay.org.uk> wrote:<br>> ><br>> >Presumably that's true now if the SP has only SAML 1 metadata? Which is<br>> >to say, it's not making anything worse?<br>> <br>> It depends on error handling and discovery, but yes, in some sense it<br>> might just be changing where the error shows up. But that would be a sign<br>> of a discovery problem in terms of how things are deployed. If you give<br>> users the option to pick an IdP that doesn't actually work for your<br>> system, then of course it will break but that's a fixable issue by<br>> changing discovery.<br>> <br>> -- Scott<br>> <br>> <br>> --<br>> To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br></div></div></div>                                            </div></body>
</html>