<html><body><div style="color:#000; background-color:#fff; font-family:arial, helvetica, sans-serif;font-size:12pt"><div><span>Currently, we authenticate at the enterprise level - when a request comes in, we use the IDp's entityID to look up the associated account and log the user in under that, then use the user specific attributes to personalize the user's experience. &nbsp;In this hub and spoke scenario, would I need to have an attribute passed that indicates the specific enterprise attempting access since I only have the single federation based entityID?</span></div><div><br></div>  <div style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"> <div style="font-family: 'times new roman', 'new york', times, serif; font-size: 12pt;"> <div dir="ltr"> <hr size="1">  <font size="2" face="Arial"> <b><span style="font-weight:bold;">From:</span></b> "Cantor, Scott" &lt;cantor.2@osu.edu&gt;<br> <b><span style="font-weight: bold;">To:</span></b>
 Shib Users &lt;users@shibboleth.net&gt; <br> <b><span style="font-weight: bold;">Sent:</span></b> Monday, May 13, 2013 11:28 AM<br> <b><span style="font-weight: bold;">Subject:</span></b> Re: School me on hub and spoke federations<br> </font> </div> <div class="y_msg_container"><br>On 5/13/13 2:12 PM, "Mike Flynn" &lt;<a ymailto="mailto:shibbolethlynda@yahoo.com" href="mailto:shibbolethlynda@yahoo.com">shibbolethlynda@yahoo.com</a>&gt; wrote:<br><br>&gt;Was recently asked to look at Kennisnet.nl as federation for another<br>&gt;client.&nbsp; Looking at their fed they call it a "hub and spoke" federation.<br>&gt;Their metadata only consists of a single SP/Idp pair that Kennisnet<br>&gt;maintains.&nbsp; Does not look to work like the<br>&gt; more traditional federations (a'la InCommon etc).<br>&gt;<br>&gt;Google has been pretty worthless trying to get information on how this<br>&gt;type of federation works.&nbsp; Can anyone enlighten me?<br><br>There's no
 single model. Most of them tend to be opaque and you're dealing<br>with just that one IdP for everything, so it may well look like a single<br>IdP. Some are more complex and are capable of simulating an end to end<br>federation so that you're effectively seeing the same thing you normally<br>would. It's likely given that metadata that it's more the former.<br><br>-- Scott<br><br><br>--<br>To unsubscribe from this list send an email to <a ymailto="mailto:users-unsubscribe@shibboleth.net" href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br><br><br></div> </div> </div>  </div></body></html>