<div dir="ltr">Hi,<br><div><div class="gmail_extra"><br></div><div class="gmail_extra">Thanks so much for your responses…<br></div><div class="gmail_extra"><br><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">

You should probably determine why you&#39;re mistaken. You do NOT have a<br>
system that would ever respond to an SP without metadata provided, so your<br>
impression that that works is incorrect.<br></blockquote><div><br></div><div>Can you help me determine why I&#39;m mistaken? If I go to the SP&#39;s URL and click to login I see that I&#39;m taken to my shibboleth IdP and sent back to them and the vendor claims I&#39;m logged in and is in possession of the attribute I released to them. I assumed that since I&#39;m able to login that it&#39;s working…<br>
</div><div><br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
<div class="im">Then it wouldn&#39;t be released, but there is no evidence of who an SP is<br></div>
without metadata, and that&#39;s the meaning of anonymous.<br>
</blockquote><div><br></div><div>Do you mean that without metadata my configuration would work but that anyone could spoof being the SP and use the IdP to gain access to attributes? And if so how does creating a metadata file for them prevent that? Or do you mean something else?<br>
<br></div><div>Sorry, I&#39;m a bit new at using Shibboleth! I have it up and running, but don&#39;t fully understand all the intricacies yet. Some SP vendors are easier to work with than others!<br></div><div><br></div><div>
Thanks again,<br></div><div>Ian <br></div></div></div></div></div>