Thanks, Scott. It's important that the URL's be separate so that we can
<br/>automatically determine each user's tenant ID based on the URL. Given
<br/>that fact, what would be a better way to configure it?
<br/><br/>On 2/25/2013 12:46 PM, Cantor, Scott E. [via Shibboleth] wrote:
<div class='shrinkable-quote'><br/>> > The problem with this is that we have to configure a new set of SP URL's
<br/>> > every time we want to enable single sign on for a tenant. This is
<br/>> because
<br/>> > when the SAML request is sent by Shib to the IdP, the ACS URL is set
<br/>> to a
<br/>> > URL with the specific sub-domain (e.g. client1.example.com).
<br/>>
<br/>> Yes, it's a bad model to do separate vhosts per tenant.
<br/>>
<br/>> > I think the lynch pin of all of this is the Shib auth cookie which is
<br/>> scoped
<br/>> > to the specific sub-domain. If I can configure Shib SP to set a
<br/>> high-level
<br/>> > cookie (.example.com) instead of a sub-domain level cookie
<br/>> > (clientx.example.com), then I should be able to redirect the user to
<br/>>
<br/>> Yes, and then all your tenants are sharing a cookie domain. I don't
<br/>> think you really want to do that. But you certainly can if you want.
<br/>>
<br/>> -- Scott
<br/>>
<br/>>
<br/>> --
<br/>> To unsubscribe from this list send an email to [hidden email]
<br/>> </user/SendEmail.jtp?type=node&node=7584794&i=0>
<br/>>
<br/>>
<br/>> ------------------------------------------------------------------------
<br/>> If you reply to this email, your message will be added to the discussion
<br/>> below:
<br/>> <a href="http://shibboleth.1660669.n2.nabble.com/Sub-domain-per-Entity-tp7584793p7584794.html" target="_top" rel="nofollow" link="external">http://shibboleth.1660669.n2.nabble.com/Sub-domain-per-Entity-tp7584793p7584794.html</a><br/>>
<br/>> To unsubscribe from Sub-domain per Entity, click here
<br/>> <<a href="" target="_top" rel="nofollow" link="external">
<br/>> NAML
<br/>> <<a href="http://shibboleth.1660669.n2.nabble.com/template/NamlServlet.jtp?macro=macro_viewer&id=instant_html%21nabble%3Aemail.naml&base=nabble.naml.namespaces.BasicNamespace-nabble.view.web.template.NabbleNamespace-nabble.view.web.template.NodeNamespace&breadcrumbs=notify_subscribers%21nabble%3Aemail.naml-instant_emails%21nabble%3Aemail.naml-send_instant_email%21nabble%3Aemail.naml" target="_top" rel="nofollow" link="external">http://shibboleth.1660669.n2.nabble.com/template/NamlServlet.jtp?macro=macro_viewer&id=instant_html%21nabble%3Aemail.naml&base=nabble.naml.namespaces.BasicNamespace-nabble.view.web.template.NabbleNamespace-nabble.view.web.template.NodeNamespace&breadcrumbs=notify_subscribers%21nabble%3Aemail.naml-instant_emails%21nabble%3Aemail.naml-send_instant_email%21nabble%3Aemail.naml</a>>
<br/>>
</div><br/>
        
        
        
<br/><hr align="left" width="300" />
View this message in context: <a href="http://shibboleth.1660669.n2.nabble.com/Sub-domain-per-Entity-tp7584793p7584795.html">Re: Sub-domain per Entity</a><br/>
Sent from the <a href="http://shibboleth.1660669.n2.nabble.com/Shibboleth-Users-f1660767.html">Shibboleth - Users mailing list archive</a> at Nabble.com.<br/>