<html><head><meta http-equiv="Content-Type" content="text/html charset=windows-1252"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; ">Mauro,<br><br>Resending this because I don't think the first edition got through...<br><br><blockquote type="cite">Actually, I followed this guide&nbsp;<a href="http://www.microsoft.com/en-us/download/details.aspx?id=35464">http://www.microsoft.com/en-us/download/details.aspx?id=35464</a>&nbsp;that on page 47 says<br></blockquote><br>Fascinating. &nbsp;This guide looks like it overlaps a lot with, but is completely distinct from:<br><br><a href="http://technet.microsoft.com/en-us/library/jj205456">http://technet.microsoft.com/en-us/library/jj205456</a><br><br><blockquote type="cite">c. &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Leave What scope will the IdP assert ? empty<br><br></blockquote><br>This will usually cause issues and I'm surprised it's in the documentation. &nbsp;Jean-Marie, one of the authors, knows his stuff, so I'll be curious to find out why this was written.<br><br><blockquote type="cite">I will inform the authors, however I left an empty scope because I didn’t want that some users were filtered out.<br></blockquote><br>I'm not sure what you mean by users being filtered out. &nbsp;The scope entered in that dialog is used to automagically append domains to some attributes in a default configuration(e.g. using uid to build an EPPN) and is also used to generate the example metadata.<br><br>My suspicion is that they never planned on using the metadata generated by the IdP and they were going to store attributes with a scope in the upstream data source. &nbsp;I still don't think that entering a scope would hurt anything, though.<br><br><blockquote type="cite">In fact, even though my AD domain name is “shibbo-domain.local”, I defined AD users like&nbsp;<a href="mailto:john.smith@eduteamit.net">john.smith@eduteamit.net</a>&nbsp;&nbsp;and<a href="mailto:paul.brown@otherdomain.com">paul.brown@otherdomain.com</a>&nbsp;and so I didn’t know what to write there, during Shibboleth installation. I probably misunderstood the point, but I supposed that my users’ domain should match the scope I write there, shound’t it?<br></blockquote><br>Yes, it should, and I think you understand. &nbsp;The scope validation is used to ensure that the IdP is authoritative over the attribute values it asserts. &nbsp;This prevents, for example,&nbsp;<a href="http://idp.osu.edu/">idp.osu.edu</a>&nbsp;from asserting&nbsp;<a href="mailto:ndk@internet2.edu">ndk@internet2.edu</a>.<br><br><blockquote type="cite">Another QQ: where could I find the error you reported (Scope must have TextContent)? I could find only the other generic error “unable to locate metadata for provider”.<br></blockquote><br>It will register complaints about metadata validation failures during startup of the SP. &nbsp;At runtime, it has no way of knowing that this entityID was defined in an unparseable file, so it just reports that it can't locate metadata for that provider.<br><br><blockquote type="cite">Thank you so much,<br></blockquote><br>Glad to help.<br>Nate.</body></html>