<html><body><div style="color:#000; background-color:#fff; font-family:arial, helvetica, sans-serif;font-size:12pt"><div><span>So, for each member coming through this fed, I have to add a new relying party rule? &nbsp;I can't match on .edu.au as other schools need to come in as private feds.</span></div><div><br></div>  <div style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"> <div style="font-family: 'times new roman', 'new york', times, serif; font-size: 12pt;"> <div dir="ltr"> <font size="2" face="Arial"> <hr size="1">  <b><span style="font-weight:bold;">From:</span></b> "Cantor, Scott" &lt;cantor.2@osu.edu&gt;<br> <b><span style="font-weight: bold;">To:</span></b> Shib Users &lt;users@shibboleth.net&gt; <br> <b><span style="font-weight: bold;">Sent:</span></b> Tuesday, January 22, 2013 5:18 PM<br> <b><span style="font-weight: bold;">Subject:</span></b> Re: Internation dateline issue<br> </font> </div> <br>
On 1/22/13 8:00 PM, "Mike Flynn" &lt;<a ymailto="mailto:shibbolethlynda@yahoo.com" href="mailto:shibbolethlynda@yahoo.com">shibbolethlynda@yahoo.com</a>&gt; wrote:<br><br>&gt;Now it looks like a cert issue...<br><br>Are you actually signing requests for some reason?<br><br>&gt;We joined the AAF and as part of that process, the AAF required that we<br>&gt;create a new cert that used our entityID instead of our base domain.<br><br>Sigh.<br><br>&gt;&nbsp; So, I created a new one:<br><br>That isn't going to matter. It's not going to choose it for signing unless<br>you create a relying party rule to make it choose that. Otherwise it's<br>going to use the first one it finds for everything.<br><br>But my primary advice would be to stop signing your requests unless you<br>have a reason for doing so.<br><br>-- Scott<br><br><br>--<br>To unsubscribe from this list send an email to <a ymailto="mailto:users-unsubscribe@shibboleth.net"
 href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br><br><br> </div> </div>  </div></body></html>