<html><head><meta http-equiv="Content-Type" content="text/html charset=iso-8859-1"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; "><br><div><div>On Mon, 7 Jan 2013, at 18:45 , Christopher Bongaarts &lt;<a href="mailto:cab@umn.edu">cab@umn.edu</a>&gt; wrote:</div><br class="Apple-interchange-newline"><blockquote type="cite">
  
    <meta content="text/html; charset=ISO-8859-1" http-equiv="Content-Type">
  
  <div text="#000000" bgcolor="#FFFFFF">
    <div class="moz-cite-prefix">On 1/7/2013 3:38 PM, David Bantz wrote:<br>
    </div>
    <blockquote cite="mid:7A172861-E69C-4532-9A68-3DDD6D31B8DC@Alaska.edu" type="cite">
      <meta http-equiv="Content-Type" content="text/html;
        charset=ISO-8859-1">
      <div>(1) Since the entityID is a name, not a location, seems that
        should be do-able without changing the IdP config - right?</div></blockquote></div></blockquote><br><blockquote type="cite"><div text="#000000" bgcolor="#FFFFFF"><blockquote cite="mid:7A172861-E69C-4532-9A68-3DDD6D31B8DC@Alaska.edu" type="cite">
    </blockquote>
    As already noted, yes, that's doable, but ensure the IdP gets
    updated metadata with endpoints corresponding to the new domain They
    can be added to the existing endpoints ahead of time to minimize
    coordination.<br>
    <pre class="moz-signature" cols="72">-- 
%%  Christopher A. Bongaarts   %%  <a class="moz-txt-link-abbreviated" href="mailto:cab@umn.edu">cab@umn.edu</a>          %%
</pre></div></blockquote><br></div><div>Are &nbsp;you saying I need to update portions of the SP metadata like</div><div><br></div><div><span style="font-family: monospace; font-size: 11.199999809265137px; background-color: rgb(255, 255, 255); ">&lt;init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://</span><span style="font-family: monospace; font-size: 11px; background-color: rgb(255, 255, 255); ">service.olddomain</span><span style="font-family: monospace; font-size: 11.199999809265137px; background-color: rgb(255, 255, 255); ">.edu/Shibboleth.sso/Login"/&gt;</span></div><div><span style="font-family: monospace; font-size: 11.199999809265137px; background-color: rgb(255, 255, 255); "><br></span></div><div><span style="font-family: monospace; font-size: 11.199999809265137px; background-color: rgb(255, 255, 255); ">and</span></div><div><br></div><div><span style="font-family: monospace; font-size: 11.199999809265137px; background-color: rgb(255, 255, 255); ">&lt;md:</span><span style="font-family: monospace; font-size: 11.199999809265137px; background-color: rgb(255, 255, 255); ">AssertionConsumerService</span><span style="font-family: monospace; font-size: 11.199999809265137px; background-color: rgb(255, 255, 255); ">&nbsp;Binding="urn:oasis:names:tc:SAML:2.0:bindings:</span><span style="font-family: monospace; font-size: 11.199999809265137px; background-color: rgb(255, 255, 255); ">HTTP-POST</span><span style="font-family: monospace; font-size: 11.199999809265137px; background-color: rgb(255, 255, 255); ">" Location="<a href="https://service.olddomain.edu/Shibboleth.sso/">https://service.olddomain.edu/Shibboleth.sso/</a></span><span style="font-family: monospace; font-size: 11.199999809265137px; background-color: rgb(255, 255, 255); ">SAML2/POST</span><span style="font-family: monospace; font-size: 11.199999809265137px; background-color: rgb(255, 255, 255); ">"/&gt;</span></div><div><br></div>to reflect the new URL of the service<div><br></div><div><span style="font-family: monospace; font-size: 11.199999809265137px; background-color: rgb(255, 255, 255); ">&lt;init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="<a href="https://service.new.domain.edu/Shibboleth.sso/Login">https://service.new.domain.edu/Shibboleth.sso/Login</a>"/&gt;</span></div><div><font face="monospace"><span style="font-size: 11px;"><br></span></font></div><div><font face="monospace"><span style="font-size: 11px;">and<br></span></font><div><br></div><div><span style="font-family: monospace; font-size: 11.199999809265137px; background-color: rgb(255, 255, 255); ">&lt;md:</span><span style="font-family: monospace; font-size: 11.199999809265137px; background-color: rgb(255, 255, 255); ">AssertionConsumerService</span><span style="font-family: monospace; font-size: 11.199999809265137px; background-color: rgb(255, 255, 255); ">&nbsp;Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="<a href="https://service.new.domain.edu/Shibboleth.sso/">https://service.new.domain.edu/Shibboleth.sso/</a></span><span style="font-family: monospace; font-size: 11.199999809265137px; background-color: rgb(255, 255, 255); ">SAML2/POST</span><span style="font-family: monospace; font-size: 11.199999809265137px; background-color: rgb(255, 255, 255); ">"/&gt;</span></div><div><span style="font-family: monospace; font-size: 11.199999809265137px; background-color: rgb(255, 255, 255); "><br></span></div><div><span style="background-color: rgb(255, 255, 255); "><font face="monospace"><span style="font-size: 11.199999809265137px;">even&nbsp;</span><span style="font-size: 11px;">though</span><span style="font-size: 11.199999809265137px;">&nbsp;the entityID remains <a href="https://service.olddomain.edu/shibboleth">https://service.olddomain.edu/shibboleth</a> ?</span></font></span></div><div><span style="background-color: rgb(255, 255, 255); "><font face="monospace"><span style="font-size: 11.199999809265137px;"><br></span></font></span></div><div><span style="background-color: rgb(255, 255, 255); "><font face="monospace"><span style="font-size: 11.199999809265137px;">David Bantz</span></font></span></div></div></body></html>