<html><head><meta http-equiv="Content-Type" content="text/html charset=iso-8859-1"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; "><br><div><div>On Mon, 7 Jan 2013, at 18:45 , Christopher Bongaarts <<a href="mailto:cab@umn.edu">cab@umn.edu</a>> wrote:</div><br class="Apple-interchange-newline"><blockquote type="cite">
<meta content="text/html; charset=ISO-8859-1" http-equiv="Content-Type">
<div text="#000000" bgcolor="#FFFFFF">
<div class="moz-cite-prefix">On 1/7/2013 3:38 PM, David Bantz wrote:<br>
</div>
<blockquote cite="mid:7A172861-E69C-4532-9A68-3DDD6D31B8DC@Alaska.edu" type="cite">
<meta http-equiv="Content-Type" content="text/html;
charset=ISO-8859-1">
<div>(1) Since the entityID is a name, not a location, seems that
should be do-able without changing the IdP config - right?</div></blockquote></div></blockquote><br><blockquote type="cite"><div text="#000000" bgcolor="#FFFFFF"><blockquote cite="mid:7A172861-E69C-4532-9A68-3DDD6D31B8DC@Alaska.edu" type="cite">
</blockquote>
As already noted, yes, that's doable, but ensure the IdP gets
updated metadata with endpoints corresponding to the new domain They
can be added to the existing endpoints ahead of time to minimize
coordination.<br>
<pre class="moz-signature" cols="72">--
%% Christopher A. Bongaarts %% <a class="moz-txt-link-abbreviated" href="mailto:cab@umn.edu">cab@umn.edu</a> %%
</pre></div></blockquote><br></div><div>Are you saying I need to update portions of the SP metadata like</div><div><br></div><div><span style="font-family: monospace; font-size: 11.199999809265137px; background-color: rgb(255, 255, 255); "><init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://</span><span style="font-family: monospace; font-size: 11px; background-color: rgb(255, 255, 255); ">service.olddomain</span><span style="font-family: monospace; font-size: 11.199999809265137px; background-color: rgb(255, 255, 255); ">.edu/Shibboleth.sso/Login"/></span></div><div><span style="font-family: monospace; font-size: 11.199999809265137px; background-color: rgb(255, 255, 255); "><br></span></div><div><span style="font-family: monospace; font-size: 11.199999809265137px; background-color: rgb(255, 255, 255); ">and</span></div><div><br></div><div><span style="font-family: monospace; font-size: 11.199999809265137px; background-color: rgb(255, 255, 255); "><md:</span><span style="font-family: monospace; font-size: 11.199999809265137px; background-color: rgb(255, 255, 255); ">AssertionConsumerService</span><span style="font-family: monospace; font-size: 11.199999809265137px; background-color: rgb(255, 255, 255); "> Binding="urn:oasis:names:tc:SAML:2.0:bindings:</span><span style="font-family: monospace; font-size: 11.199999809265137px; background-color: rgb(255, 255, 255); ">HTTP-POST</span><span style="font-family: monospace; font-size: 11.199999809265137px; background-color: rgb(255, 255, 255); ">" Location="<a href="https://service.olddomain.edu/Shibboleth.sso/">https://service.olddomain.edu/Shibboleth.sso/</a></span><span style="font-family: monospace; font-size: 11.199999809265137px; background-color: rgb(255, 255, 255); ">SAML2/POST</span><span style="font-family: monospace; font-size: 11.199999809265137px; background-color: rgb(255, 255, 255); ">"/></span></div><div><br></div>to reflect the new URL of the service<div><br></div><div><span style="font-family: monospace; font-size: 11.199999809265137px; background-color: rgb(255, 255, 255); "><init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="<a href="https://service.new.domain.edu/Shibboleth.sso/Login">https://service.new.domain.edu/Shibboleth.sso/Login</a>"/></span></div><div><font face="monospace"><span style="font-size: 11px;"><br></span></font></div><div><font face="monospace"><span style="font-size: 11px;">and<br></span></font><div><br></div><div><span style="font-family: monospace; font-size: 11.199999809265137px; background-color: rgb(255, 255, 255); "><md:</span><span style="font-family: monospace; font-size: 11.199999809265137px; background-color: rgb(255, 255, 255); ">AssertionConsumerService</span><span style="font-family: monospace; font-size: 11.199999809265137px; background-color: rgb(255, 255, 255); "> Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="<a href="https://service.new.domain.edu/Shibboleth.sso/">https://service.new.domain.edu/Shibboleth.sso/</a></span><span style="font-family: monospace; font-size: 11.199999809265137px; background-color: rgb(255, 255, 255); ">SAML2/POST</span><span style="font-family: monospace; font-size: 11.199999809265137px; background-color: rgb(255, 255, 255); ">"/></span></div><div><span style="font-family: monospace; font-size: 11.199999809265137px; background-color: rgb(255, 255, 255); "><br></span></div><div><span style="background-color: rgb(255, 255, 255); "><font face="monospace"><span style="font-size: 11.199999809265137px;">even </span><span style="font-size: 11px;">though</span><span style="font-size: 11.199999809265137px;"> the entityID remains <a href="https://service.olddomain.edu/shibboleth">https://service.olddomain.edu/shibboleth</a> ?</span></font></span></div><div><span style="background-color: rgb(255, 255, 255); "><font face="monospace"><span style="font-size: 11.199999809265137px;"><br></span></font></span></div><div><span style="background-color: rgb(255, 255, 255); "><font face="monospace"><span style="font-size: 11.199999809265137px;">David Bantz</span></font></span></div></div></body></html>