Thanks, Scott. It's important that the URL's be separate so that we can 
<br/>automatically determine each user's tenant ID based on the URL. Given 
<br/>that fact, what would be a better way to configure it?
<br/><br/>On 2/25/2013 12:46 PM, Cantor, Scott E. [via Shibboleth] wrote:
<div class='shrinkable-quote'><br/>&gt; &nbsp;&gt; The problem with this is that we have to configure a new set of SP URL's
<br/>&gt; &nbsp;&gt; every time we want to enable single sign on for a tenant. This is
<br/>&gt; because
<br/>&gt; &nbsp;&gt; when the SAML request is sent by Shib to the IdP, the ACS URL is set
<br/>&gt; to a
<br/>&gt; &nbsp;&gt; URL with the specific sub-domain (e.g. client1.example.com).
<br/>&gt;
<br/>&gt; Yes, it's a bad model to do separate vhosts per tenant.
<br/>&gt;
<br/>&gt; &nbsp;&gt; I think the lynch pin of all of this is the Shib auth cookie which is
<br/>&gt; scoped
<br/>&gt; &nbsp;&gt; to the specific sub-domain. If I can configure Shib SP to set a
<br/>&gt; high-level
<br/>&gt; &nbsp;&gt; cookie (.example.com) instead of a sub-domain level cookie
<br/>&gt; &nbsp;&gt; (clientx.example.com), then I should be able to redirect the user to
<br/>&gt;
<br/>&gt; Yes, and then all your tenants are sharing a cookie domain. I don't
<br/>&gt; think you really want to do that. But you certainly can if you want.
<br/>&gt;
<br/>&gt; -- Scott
<br/>&gt;
<br/>&gt;
<br/>&gt; --
<br/>&gt; To unsubscribe from this list send an email to [hidden email]
<br/>&gt; &lt;/user/SendEmail.jtp?type=node&amp;node=7584794&amp;i=0&gt;
<br/>&gt;
<br/>&gt;
<br/>&gt; ------------------------------------------------------------------------
<br/>&gt; If you reply to this email, your message will be added to the discussion
<br/>&gt; below:
<br/>&gt; <a href="http://shibboleth.1660669.n2.nabble.com/Sub-domain-per-Entity-tp7584793p7584794.html" target="_top" rel="nofollow" link="external">http://shibboleth.1660669.n2.nabble.com/Sub-domain-per-Entity-tp7584793p7584794.html</a><br/>&gt;
<br/>&gt; To unsubscribe from Sub-domain per Entity, click here
<br/>&gt; &lt;<a href="" target="_top" rel="nofollow" link="external">
<br/>&gt; NAML
<br/>&gt; &lt;<a href="http://shibboleth.1660669.n2.nabble.com/template/NamlServlet.jtp?macro=macro_viewer&id=instant_html%21nabble%3Aemail.naml&base=nabble.naml.namespaces.BasicNamespace-nabble.view.web.template.NabbleNamespace-nabble.view.web.template.NodeNamespace&breadcrumbs=notify_subscribers%21nabble%3Aemail.naml-instant_emails%21nabble%3Aemail.naml-send_instant_email%21nabble%3Aemail.naml" target="_top" rel="nofollow" link="external">http://shibboleth.1660669.n2.nabble.com/template/NamlServlet.jtp?macro=macro_viewer&amp;id=instant_html%21nabble%3Aemail.naml&amp;base=nabble.naml.namespaces.BasicNamespace-nabble.view.web.template.NabbleNamespace-nabble.view.web.template.NodeNamespace&amp;breadcrumbs=notify_subscribers%21nabble%3Aemail.naml-instant_emails%21nabble%3Aemail.naml-send_instant_email%21nabble%3Aemail.naml</a>&gt;
<br/>&gt;
</div><br/>

        
        
        
<br/><hr align="left" width="300" />
View this message in context: <a href="http://shibboleth.1660669.n2.nabble.com/Sub-domain-per-Entity-tp7584793p7584795.html">Re: Sub-domain per Entity</a><br/>
Sent from the <a href="http://shibboleth.1660669.n2.nabble.com/Shibboleth-Users-f1660767.html">Shibboleth - Users mailing list archive</a> at Nabble.com.<br/>