We are a brand new sign up to the Net+ Box service and are beginning our implementation/roll-out of which Shibboleth SSO is a large part of. I had my initial SSO talk with Box just the other day where there are a few things I&#39;m not used to on the IdP configuration side I wanted to ask about. Admittedly, the majority of our campus&#39; work with shibb has been on the IdP side and in the context of federation. I understand Box is not yet there with being able to deal with the InCommon metadata, so instead a more direct pairing of IdP + SP is needed. So my question is around the correct setup for the Box SP metadata in my IdP? Box mentioned something that was new to me... that they did not use certificates to sign their metadata as is typical of the shibb world, so we would need to give the IdP an exception to not worry about unsigned metadata (there was some mention they could sign if they had to, but would prefer for us to make the exception). Is anyone familiar with this, how to set it up, or what the Box metadata should look like? I think I can handle the appropriate attribute mappings once I&#39;m able to get the metadata and relying-party set up correctly. any examples you&#39;re willing to share would be much appreciated.<br>

<br><br>-Rob<br><br>-- <br><div>Robert W. Gorrell<br>Middleware Engineer, Identity and Access Management</div>
<div>University of NC at Greensboro<br>336-334-5954</div>