<div dir="ltr"><div>So its as I expected. </div><div> </div><div>Thanks for taking the time to reply guys. I appreciate it.</div><div> </div><div>Cheers</div><div> </div><div>M </div></div><div class="gmail_extra"><br><br>
<div class="gmail_quote">On 1 February 2013 20:34, Christopher Bongaarts <span dir="ltr">&lt;<a href="mailto:cab@umn.edu" target="_blank">cab@umn.edu</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div class="im">On 1/31/2013 11:38 AM, Matheesha Weerasinghe wrote:<br>
&gt; In Office 365 if the customer can choose to register a bunch of DNS<br>
&gt; domains they own with UPNs in the format of <a href="mailto:john@contoso.com">john@contoso.com</a><br>
</div>&gt; &lt;mailto:<a href="mailto:john@contoso.com">john@contoso.com</a>&gt; . They can then configure O365 such that it<br>
<div class="im">&gt; knows the SAML endpoint for each domain (e.g. <a href="http://contoso.com" target="_blank">contoso.com</a><br>
</div>&gt; &lt;<a href="http://contoso.com" target="_blank">http://contoso.com</a>&gt;, <a href="http://fabrikam.com" target="_blank">fabrikam.com</a> &lt;<a href="http://fabrikam.com" target="_blank">http://fabrikam.com</a>&gt;). When a user<br>

<div class="im">&gt; attempts to access O365, they will be redirected to Shibboleth which<br>
&gt; will issue a token which O365 will in turn consume and accordingly<br>
&gt; allow/deny access to the service.<br>
&gt; In configuring the EntityID for each of these domains, there is a<br>
&gt; requirement to ensure each one is unique. This presents a problem if the<br>
&gt; customer has several domains but wants to use one Shibboleth<br>
&gt; implementation to handle the authentication for all of them. AFAIK, you<br>
&gt; can only define one relying party in the XML. This means Shibboleth will<br>
&gt; always send the same relying party regardless of the user it issued the<br>
&gt; token for.<br>
<br>
</div>I don&#39;t know about O365, but for Google Apps, each &quot;domain&quot; on the<br>
google side has its own entity ID (i.e. each is effectively a separate<br>
SP/RP).<br>
<br>
The Shibboleth IdP is able to use a different entity ID for itself<br>
depending on the calling SP/RP (you just set up multiple RelyingParty<br>
entries in relying-party.xml).<br>
<span class="HOEnZb"><font color="#888888"><br>
--<br>
%%  Christopher A. Bongaarts   %%  <a href="mailto:cab@umn.edu">cab@umn.edu</a>          %%<br>
%%  OIT - Identity Management  %%  <a href="http://umn.edu/~cab" target="_blank">http://umn.edu/~cab</a>  %%<br>
%%  University of Minnesota    %%  <a href="tel:%2B1%20%28612%29%20625-1809" value="+16126251809">+1 (612) 625-1809</a>    %%<br>
</font></span><div class="HOEnZb"><div class="h5">--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br></div>