<html><head><meta http-equiv="Content-Type" content="text/html charset=windows-1252"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; ">Mauro,<br><br>Resending this because I don't think the first edition got through...<br><br><blockquote type="cite">Actually, I followed this guide <a href="http://www.microsoft.com/en-us/download/details.aspx?id=35464">http://www.microsoft.com/en-us/download/details.aspx?id=35464</a> that on page 47 says<br></blockquote><br>Fascinating. This guide looks like it overlaps a lot with, but is completely distinct from:<br><br><a href="http://technet.microsoft.com/en-us/library/jj205456">http://technet.microsoft.com/en-us/library/jj205456</a><br><br><blockquote type="cite">c. Leave What scope will the IdP assert ? empty<br><br></blockquote><br>This will usually cause issues and I'm surprised it's in the documentation. Jean-Marie, one of the authors, knows his stuff, so I'll be curious to find out why this was written.<br><br><blockquote type="cite">I will inform the authors, however I left an empty scope because I didn’t want that some users were filtered out.<br></blockquote><br>I'm not sure what you mean by users being filtered out. The scope entered in that dialog is used to automagically append domains to some attributes in a default configuration(e.g. using uid to build an EPPN) and is also used to generate the example metadata.<br><br>My suspicion is that they never planned on using the metadata generated by the IdP and they were going to store attributes with a scope in the upstream data source. I still don't think that entering a scope would hurt anything, though.<br><br><blockquote type="cite">In fact, even though my AD domain name is “shibbo-domain.local”, I defined AD users like <a href="mailto:john.smith@eduteamit.net">john.smith@eduteamit.net</a> and<a href="mailto:paul.brown@otherdomain.com">paul.brown@otherdomain.com</a> and so I didn’t know what to write there, during Shibboleth installation. I probably misunderstood the point, but I supposed that my users’ domain should match the scope I write there, shound’t it?<br></blockquote><br>Yes, it should, and I think you understand. The scope validation is used to ensure that the IdP is authoritative over the attribute values it asserts. This prevents, for example, <a href="http://idp.osu.edu/">idp.osu.edu</a> from asserting <a href="mailto:ndk@internet2.edu">ndk@internet2.edu</a>.<br><br><blockquote type="cite">Another QQ: where could I find the error you reported (Scope must have TextContent)? I could find only the other generic error “unable to locate metadata for provider”.<br></blockquote><br>It will register complaints about metadata validation failures during startup of the SP. At runtime, it has no way of knowing that this entityID was defined in an unparseable file, so it just reports that it can't locate metadata for that provider.<br><br><blockquote type="cite">Thank you so much,<br></blockquote><br>Glad to help.<br>Nate.</body></html>