<div dir="ltr"><span class="" style>ShibUsers</span>,<div><br></div><div>We&#39;re finally getting around to cleaning up our <span class="" style>metadata</span> file.</div><div>We&#39;re SP only so this is the file that we&#39;d have our partner/customer <span class="" style>IdP</span> servers install.</div>
<div><br></div><div>We&#39;ve looked at examples for everywhere and we&#39;re still confused.</div><div><br></div><div>The ../Shibboleth.<span class="" style>sso</span>/<span class="" style>Metadata</span> generated file has a familiar structure:</div>
<div><br></div><div>(We know this will not be the final file, but just a starting point)</div><div><br></div><div><br></div><div><div><br></div><div>&lt;!--</div><div>This is example <span class="" style>metadata</span> only. Do *NOT* supply it as is without review,</div>
<div>and do *NOT* provide it in real time to your partners.</div><div> --&gt;</div><div>&lt;<span class="" style>md</span>:<span class="" style>EntityDescriptor</span> <span class="" style>xmlns</span>:<span class="" style>md</span>=&quot;urn:oasis:names:<span class="" style>tc</span>:<span class="" style>SAML</span>:2.0:<span class="" style>metadata</span>&quot; ID=&quot;_7f02024667d46287aafdd4ecdfd0627d2010938b&quot; <span class="" style>entityID</span>=&quot;<a href="https://app1.corp.com/Shibboleth">https://app1.corp.com/Shibboleth</a>.<span class="" style>sso</span>&quot;&gt;</div>
<div>  &lt;<span class="" style>md</span>:Extensions <span class="" style>xmlns</span>:<span class="" style>alg</span>=&quot;urn:oasis:names:<span class="" style>tc</span>:<span class="" style>SAML</span>:<span class="" style>metadata</span>:<span class="" style>algsupport</span>&quot;&gt;</div>
<div>    &lt;<span class="" style>alg</span>:<span class="" style>DigestMethod</span> Algorithm=&quot;<a href="http://www.w3.org/2001/04/">http://www.w3.org/2001/04/</a><span class="" style>xmlenc</span>#sha512&quot;/&gt;</div>
<div>    &lt;<span class="" style>alg</span>:<span class="" style>DigestMethod</span> Algorithm=&quot;<a href="http://www.w3.org/2001/04/">http://www.w3.org/2001/04/</a><span class="" style>xmldsig</span>-more#sha384&quot;/&gt;</div>
<div>    &lt;<span class="" style>alg</span>:<span class="" style>DigestMethod</span> Algorithm=&quot;<a href="http://www.w3.org/2001/04/">http://www.w3.org/2001/04/</a><span class="" style>xmlenc</span>#sha256&quot;/&gt;</div>
<div>    &lt;<span class="" style>alg</span>:<span class="" style>DigestMethod</span> Algorithm=&quot;<a href="http://www.w3.org/2001/04/">http://www.w3.org/2001/04/</a><span class="" style>xmldsig</span>-more#sha224&quot;/&gt;</div>
<div>    &lt;<span class="" style>alg</span>:<span class="" style>DigestMethod</span> Algorithm=&quot;<a href="http://www.w3.org/2000/09/">http://www.w3.org/2000/09/</a><span class="" style>xmldsig</span>#sha1&quot;/&gt;</div>
<div>    &lt;<span class="" style>alg</span>:<span class="" style>SigningMethod</span> Algorithm=&quot;<a href="http://www.w3.org/2001/04/">http://www.w3.org/2001/04/</a><span class="" style>xmldsig</span>-more#<span class="" style>rsa</span>-sha512&quot;/&gt;</div>
<div>    &lt;<span class="" style>alg</span>:<span class="" style>SigningMethod</span> Algorithm=&quot;<a href="http://www.w3.org/2001/04/">http://www.w3.org/2001/04/</a><span class="" style>xmldsig</span>-more#<span class="" style>rsa</span>-sha384&quot;/&gt;</div>
<div>    &lt;<span class="" style>alg</span>:<span class="" style>SigningMethod</span> Algorithm=&quot;<a href="http://www.w3.org/2001/04/">http://www.w3.org/2001/04/</a><span class="" style>xmldsig</span>-more#<span class="" style>rsa</span>-sha256&quot;/&gt;</div>
<div>    &lt;<span class="" style>alg</span>:<span class="" style>SigningMethod</span> Algorithm=&quot;<a href="http://www.w3.org/2009/xmldsig11#">http://www.w3.org/2009/xmldsig11#</a><span class="" style>dsa</span>-sha256&quot;/&gt;</div>
<div>    &lt;<span class="" style>alg</span>:<span class="" style>SigningMethod</span> Algorithm=&quot;<a href="http://www.w3.org/2000/09/">http://www.w3.org/2000/09/</a><span class="" style>xmldsig</span>#<span class="" style>rsa</span>-sha1&quot;/&gt;</div>
<div>    &lt;<span class="" style>alg</span>:<span class="" style>SigningMethod</span> Algorithm=&quot;<a href="http://www.w3.org/2000/09/">http://www.w3.org/2000/09/</a><span class="" style>xmldsig</span>#<span class="" style>dsa</span>-sha1&quot;/&gt;</div>
<div>  &lt;/<span class="" style>md</span>:Extensions&gt;</div><div>  &lt;<span class="" style>md</span>:<span class="" style>SPSSODescriptor</span> <span class="" style>protocolSupportEnumeration</span>=&quot;urn:oasis:names:<span class="" style>tc</span>:<span class="" style>SAML</span>:2.0:protocol urn:oasis:names:<span class="" style>tc</span>:<span class="" style>SAML</span>:1.1:protocol urn:oasis:names:<span class="" style>tc</span>:<span class="" style>SAML</span>:1.0:protocol&quot;&gt;</div>
<div>    &lt;<span class="" style>md</span>:Extensions&gt;</div><div>      &lt;<span class="" style>init</span>:<span class="" style>RequestInitiator</span> <span class="" style>xmlns</span>:<span class="" style>init</span>=&quot;urn:oasis:names:<span class="" style>tc</span>:<span class="" style>SAML</span>:profiles:<span class="" style>SSO</span>:request-<span class="" style>init</span>&quot; Binding=&quot;urn:oasis:names:<span class="" style>tc</span>:<span class="" style>SAML</span>:profiles:<span class="" style>SSO</span>:request-<span class="" style>init</span>&quot; Location=&quot;<a href="https://app1.corp.com/Shibboleth">https://app1.corp.com/Shibboleth</a>.<span class="" style>sso</span>/<span class="" style>Login</span>&quot;/&gt;</div>
<div>    &lt;/<span class="" style>md</span>:Extensions&gt;</div><div>    &lt;<span class="" style>md</span>:<span class="" style>KeyDescriptor</span>&gt;</div><div>      &lt;<span class="" style>ds</span>:<span class="" style>KeyInfo</span> <span class="" style>xmlns</span>:<span class="" style>ds</span>=&quot;<a href="http://www.w3.org/2000/09/">http://www.w3.org/2000/09/</a><span class="" style>xmldsig</span>#&quot;&gt;</div>
<div>        &lt;<span class="" style>ds</span>:<span class="" style>KeyName</span>&gt;CBRDWEBP07&lt;/<span class="" style>ds</span>:<span class="" style>KeyName</span>&gt;</div><div>        &lt;<span class="" style>ds</span>:X509Data&gt;</div>
<div>          &lt;<span class="" style>ds</span>:X509SubjectName&gt;<span class="" style>CN</span>=CBRDWEBP07&lt;/<span class="" style>ds</span>:X509SubjectName&gt;</div><div>          &lt;<span class="" style>ds</span>:X509Certificate&gt;<span class="" style>dklsfjklsdfkljslf</span>;<span class="" style>fjsfjweiorjds</span>;f;<span class="" style>JSDFSDFJ</span>;<span class="" style>ASDFSJDF</span></div>
<div><br></div><div>&lt;CERT LINES HERE&gt;</div><div><br></div><div><span class="" style>dklsfjklsdfkljslf</span>;<span class="" style>fjsfjweiorjds</span>;f;<span class="" style>JSDFSDFJ</span>;<span class="" style>ASDFSJDF</span>==</div>
<div>&lt;/<span class="" style>ds</span>:X509Certificate&gt;</div><div>        &lt;/<span class="" style>ds</span>:X509Data&gt;</div><div>      &lt;/<span class="" style>ds</span>:<span class="" style>KeyInfo</span>&gt;</div>
<div>      &lt;<span class="" style>md</span>:<span class="" style>EncryptionMethod</span> Algorithm=&quot;<a href="http://www.w3.org/2001/04/">http://www.w3.org/2001/04/</a><span class="" style>xmlenc</span>#aes128-<span class="" style>cbc</span>&quot;/&gt;</div>
<div>      &lt;<span class="" style>md</span>:<span class="" style>EncryptionMethod</span> Algorithm=&quot;<a href="http://www.w3.org/2001/04/">http://www.w3.org/2001/04/</a><span class="" style>xmlenc</span>#aes192-<span class="" style>cbc</span>&quot;/&gt;</div>
<div>      &lt;<span class="" style>md</span>:<span class="" style>EncryptionMethod</span> Algorithm=&quot;<a href="http://www.w3.org/2001/04/">http://www.w3.org/2001/04/</a><span class="" style>xmlenc</span>#aes256-<span class="" style>cbc</span>&quot;/&gt;</div>
<div>      &lt;<span class="" style>md</span>:<span class="" style>EncryptionMethod</span> Algorithm=&quot;<a href="http://www.w3.org/2001/04/">http://www.w3.org/2001/04/</a><span class="" style>xmlenc</span>#<span class="" style>tripledes</span>-<span class="" style>cbc</span>&quot;/&gt;</div>
<div>      &lt;<span class="" style>md</span>:<span class="" style>EncryptionMethod</span> Algorithm=&quot;<a href="http://www.w3.org/2009/xmlenc11#">http://www.w3.org/2009/xmlenc11#</a><span class="" style>rsa</span>-<span class="" style>oaep</span>&quot;/&gt;</div>
<div>      &lt;<span class="" style>md</span>:<span class="" style>EncryptionMethod</span> Algorithm=&quot;<a href="http://www.w3.org/2001/04/">http://www.w3.org/2001/04/</a><span class="" style>xmlenc</span>#<span class="" style>rsa</span>-<span class="" style>oaep</span>-mgf1p&quot;/&gt;</div>
<div>    &lt;/<span class="" style>md</span>:<span class="" style>KeyDescriptor</span>&gt;</div><div>    &lt;<span class="" style>md</span>:<span class="" style>ArtifactResolutionService</span> Binding=&quot;urn:oasis:names:<span class="" style>tc</span>:<span class="" style>SAML</span>:2.0:bindings:SOAP&quot; Location=&quot;<a href="https://app1.corp.com/Shibboleth">https://app1.corp.com/Shibboleth</a>.<span class="" style>sso</span>/Artifact/SOAP&quot; index=&quot;1&quot;/&gt;</div>
<div>    &lt;<span class="" style>md</span>:<span class="" style>SingleLogoutService</span> Binding=&quot;urn:oasis:names:<span class="" style>tc</span>:<span class="" style>SAML</span>:2.0:bindings:SOAP&quot; Location=&quot;<a href="https://app1.corp.com/Shibboleth">https://app1.corp.com/Shibboleth</a>.<span class="" style>sso</span>/<span class="" style>SLO</span>/SOAP&quot;/&gt;</div>
<div>    &lt;<span class="" style>md</span>:<span class="" style>SingleLogoutService</span> Binding=&quot;urn:oasis:names:<span class="" style>tc</span>:<span class="" style>SAML</span>:2.0:bindings:HTTP-Redirect&quot; Location=&quot;<a href="https://app1.corp.com/Shibboleth">https://app1.corp.com/Shibboleth</a>.<span class="" style>sso</span>/<span class="" style>SLO</span>/Redirect&quot;/&gt;</div>
<div>    &lt;<span class="" style>md</span>:<span class="" style>SingleLogoutService</span> Binding=&quot;urn:oasis:names:<span class="" style>tc</span>:<span class="" style>SAML</span>:2.0:bindings:HTTP-POST&quot; Location=&quot;<a href="https://app1.corp.com/Shibboleth">https://app1.corp.com/Shibboleth</a>.<span class="" style>sso</span>/<span class="" style>SLO</span>/POST&quot;/&gt;</div>
<div>    &lt;<span class="" style>md</span>:<span class="" style>SingleLogoutService</span> Binding=&quot;urn:oasis:names:<span class="" style>tc</span>:<span class="" style>SAML</span>:2.0:bindings:HTTP-Artifact&quot; Location=&quot;<a href="https://app1.corp.com/Shibboleth">https://app1.corp.com/Shibboleth</a>.<span class="" style>sso</span>/<span class="" style>SLO</span>/Artifact&quot;/&gt;</div>
<div>    &lt;<span class="" style>md</span>:<span class="" style>AssertionConsumerService</span> Binding=&quot;urn:oasis:names:<span class="" style>tc</span>:<span class="" style>SAML</span>:2.0:bindings:HTTP-POST&quot; Location=&quot;<a href="https://app1.corp.com/Shibboleth">https://app1.corp.com/Shibboleth</a>.<span class="" style>sso</span>/SAML2/POST&quot; index=&quot;1&quot;/&gt;</div>
<div>    &lt;<span class="" style>md</span>:<span class="" style>AssertionConsumerService</span> Binding=&quot;urn:oasis:names:<span class="" style>tc</span>:<span class="" style>SAML</span>:2.0:bindings:HTTP-POST-<span class="" style>SimpleSign</span>&quot; Location=&quot;<a href="https://app1.corp.com/Shibboleth">https://app1.corp.com/Shibboleth</a>.<span class="" style>sso</span>/SAML2/POST-<span class="" style>SimpleSign</span>&quot; index=&quot;2&quot;/&gt;</div>
<div>    &lt;<span class="" style>md</span>:<span class="" style>AssertionConsumerService</span> Binding=&quot;urn:oasis:names:<span class="" style>tc</span>:<span class="" style>SAML</span>:2.0:bindings:HTTP-Artifact&quot; Location=&quot;<a href="https://app1.corp.com/Shibboleth">https://app1.corp.com/Shibboleth</a>.<span class="" style>sso</span>/SAML2/Artifact&quot; index=&quot;3&quot;/&gt;</div>
<div>    &lt;<span class="" style>md</span>:<span class="" style>AssertionConsumerService</span> Binding=&quot;urn:oasis:names:<span class="" style>tc</span>:<span class="" style>SAML</span>:2.0:bindings:<span class="" style>PAOS</span>&quot; Location=&quot;<a href="https://app1.corp.com/Shibboleth">https://app1.corp.com/Shibboleth</a>.<span class="" style>sso</span>/SAML2/<span class="" style>ECP</span>&quot; index=&quot;4&quot;/&gt;</div>
<div>    &lt;<span class="" style>md</span>:<span class="" style>AssertionConsumerService</span> Binding=&quot;urn:oasis:names:<span class="" style>tc</span>:<span class="" style>SAML</span>:1.0:profiles:browser-post&quot; Location=&quot;<a href="https://app1.corp.com/Shibboleth">https://app1.corp.com/Shibboleth</a>.<span class="" style>sso</span>/<span class="" style>SAML</span>/POST&quot; index=&quot;5&quot;/&gt;</div>
<div>    &lt;<span class="" style>md</span>:<span class="" style>AssertionConsumerService</span> Binding=&quot;urn:oasis:names:<span class="" style>tc</span>:<span class="" style>SAML</span>:1.0:profiles:artifact-01&quot; Location=&quot;<a href="https://app1.corp.com/Shibboleth">https://app1.corp.com/Shibboleth</a>.<span class="" style>sso</span>/<span class="" style>SAML</span>/Artifact&quot; index=&quot;6&quot;/&gt;</div>
<div>  &lt;/<span class="" style>md</span>:<span class="" style>SPSSODescriptor</span>&gt;</div><div>  &lt;Organization&gt;</div><div>    &lt;<span class="" style>OrganizationName</span> <span class="" style>xml</span>:<span class="" style>lang</span>=&quot;en&quot;&gt;Corp.Com&lt;/<span class="" style>OrganizationName</span>&gt;</div>
<div>    &lt;<span class="" style>OrganizationDisplayName</span> <span class="" style>xml</span>:<span class="" style>lang</span>=&quot;en&quot;&gt;Corp.Com&lt;/<span class="" style>OrganizationDisplayName</span>&gt;</div>
<div>    &lt;<span class="" style>OrganizationURL</span> <span class="" style>xml</span>:<span class="" style>lang</span>=&quot;en&quot;&gt;<a href="https://www.corp.com">https://www.corp.com</a>&lt;/<span class="" style>OrganizationURL</span>&gt;</div>
<div>  &lt;/Organization&gt;</div><div>  &lt;<span class="" style>ContactPerson</span> <span class="" style>contactType</span>=&quot;administrative&quot;&gt;</div><div>    &lt;<span class="" style>GivenName</span>&gt;Mr. Administrator&lt;/<span class="" style>GivenName</span>&gt;</div>
<div>    &lt;<span class="" style>EmailAddress</span>&gt;<span class="" style>adm</span>@<a href="http://corp.com">corp.com</a>&lt;/<span class="" style>EmailAddress</span>&gt;</div><div>  &lt;/<span class="" style>ContactPerson</span>&gt;</div>
<div>  &lt;<span class="" style>ContactPerson</span> <span class="" style>contactType</span>=&quot;support&quot;&gt;</div><div>    &lt;<span class="" style>GivenName</span>&gt;Support Group&lt;/<span class="" style>GivenName</span>&gt;</div>
<div>    &lt;<span class="" style>EmailAddress</span>&gt;<a href="mailto:support@corp.com">support@corp.com</a>&lt;/<span class="" style>EmailAddress</span>&gt;</div><div>  &lt;/<span class="" style>ContactPerson</span>&gt;</div>
<div>&lt;/<span class="" style>md</span>:<span class="" style>EntityDescriptor</span>&gt;</div></div><div><br></div><div style>This worked just fine with our partners and customers.</div><div style><br></div><div style>Notice all the &quot;&lt;<span class="" style>md</span>:  ... &lt;/<span class="" style>md</span>: pairs.</div>
<div style><br></div><div style>We then added the endpoints and CERT for one of new customers. We generated their CERT  pair with <span class="" style>KEYGEN</span> and their <span class="" style>metadata</span> file with <span class="" style>METAGEN</span>. When we went to add this new meta file to the existing <span class="" style>metadata</span> file things blew up.</div>
<div style><br></div><div style><div><br></div><div><span class="" style="white-space:pre">        </span>&lt;!-- customer2301 --&gt;</div><div>&lt;<span class="" style>md</span>:<span class="" style>EntityDescriptor</span> <span class="" style>xmlns</span>:<span class="" style>md</span>=&quot;urn:oasis:names:<span class="" style>tc</span>:<span class="" style>SAML</span>:2.0:<span class="" style>metadata</span>&quot; <span class="" style>xmlns</span>:<span class="" style>ds</span>=&quot;<a href="http://www.w3.org/2000/09/">http://www.w3.org/2000/09/</a><span class="" style>xmldsig</span>#&quot; <span class="" style>entityID</span>=&quot;<a href="https://app1.corp.com/customer2301/Shibboleth">https://app1.corp.com/customer2301/Shibboleth</a>.<span class="" style>sso</span>&quot;&gt;</div>
<div>  &lt;<span class="" style>md</span>:<span class="" style>SPSSODescriptor</span> <span class="" style>protocolSupportEnumeration</span>=&quot;urn:oasis:names:<span class="" style>tc</span>:<span class="" style>SAML</span>:2.0:protocol urn:oasis:names:<span class="" style>tc</span>:<span class="" style>SAML</span>:1.1:protocol&quot;&gt;</div>
<div>    &lt;<span class="" style>md</span>:<span class="" style>KeyDescriptor</span>&gt;</div><div>      &lt;<span class="" style>ds</span>:<span class="" style>KeyInfo</span>&gt;</div><div>        &lt;<span class="" style>ds</span>:X509Data&gt;</div>
<div>          &lt;<span class="" style>ds</span>:X509Certificate&gt;</div><div>          &lt;<span class="" style>ds</span>:X509Certificate&gt;<span class="" style>dklsfjklsdfkljslf</span>;<span class="" style>fjsfjweiorjds</span>;f;<span class="" style>JSDFSDFJ</span>;<span class="" style>ASDFSJDF</span></div>
<div><br></div><div>&lt;CERT LINES HERE&gt;</div><div><br></div><div><span class="" style>dklsfjklsdfkljslf</span>;<span class="" style>fjsfjweiorjds</span>;f;<span class="" style>JSDFSDFJ</span>;<span class="" style>ASDFSJDF</span>==</div>
<div>          &lt;/<span class="" style>ds</span>:X509Certificate&gt;</div><div>        &lt;/<span class="" style>ds</span>:X509Data&gt;</div><div>      &lt;/<span class="" style>ds</span>:<span class="" style>KeyInfo</span>&gt;</div>
<div>    &lt;/<span class="" style>md</span>:<span class="" style>KeyDescriptor</span>&gt;</div><div>    &lt;<span class="" style>md</span>:<span class="" style>AssertionConsumerService</span> Binding=&quot;urn:oasis:names:<span class="" style>tc</span>:<span class="" style>SAML</span>:2.0:bindings:HTTP-POST&quot; Location=&quot;<a href="https://app1.corp.com/customer2301/Shibboleth">https://app1.corp.com/customer2301/Shibboleth</a>.<span class="" style>sso</span>/SAML2/POST&quot; index=&quot;1&quot;/&gt;</div>
<div>    &lt;<span class="" style>md</span>:<span class="" style>AssertionConsumerService</span> Binding=&quot;urn:oasis:names:<span class="" style>tc</span>:<span class="" style>SAML</span>:2.0:bindings:HTTP-POST-<span class="" style>SimpleSign</span>&quot; Location=&quot;<a href="https://app1.corp.com/customer2301/Shibboleth">https://app1.corp.com/customer2301/Shibboleth</a>.<span class="" style>sso</span>/SAML2/POST-<span class="" style>SimpleSign</span>&quot; index=&quot;2&quot;/&gt;</div>
<div>    &lt;<span class="" style>md</span>:<span class="" style>AssertionConsumerService</span> Binding=&quot;urn:oasis:names:<span class="" style>tc</span>:<span class="" style>SAML</span>:2.0:bindings:<span class="" style>PAOS</span>&quot; Location=&quot;<a href="https://app1.corp.com/customer2301/Shibboleth">https://app1.corp.com/customer2301/Shibboleth</a>.<span class="" style>sso</span>/SAML2/<span class="" style>ECP</span>&quot; index=&quot;3&quot;/&gt;</div>
<div>    &lt;<span class="" style>md</span>:<span class="" style>AssertionConsumerService</span> Binding=&quot;urn:oasis:names:<span class="" style>tc</span>:<span class="" style>SAML</span>:1.0:profiles:browser-post&quot; Location=&quot;<a href="https://app1.corp.com/customer2301/Shibboleth">https://app1.corp.com/customer2301/Shibboleth</a>.<span class="" style>sso</span>/<span class="" style>SAML</span>/POST&quot; index=&quot;4&quot;/&gt;</div>
<div>  &lt;/<span class="" style>md</span>:<span class="" style>SPSSODescriptor</span>&gt;</div><div>&lt;/<span class="" style>md</span>:<span class="" style>EntityDescriptor</span>&gt;</div><div><span class="" style="white-space:pre">        </span>&lt;!-- customer2301 --&gt;</div>
</div><div style><br></div><div style><br></div><div style>This <span class="" style>metadata</span> also has the same &lt;<span class="" style>md</span>:..&lt;/<span class="" style>md</span>  pairs. However, none of our partners or customers could import the new file. All complained that the XML was rejected.</div>
<div style><br></div><div style>We tried a XML validation tool, and it reported the problem starting at the new addition (not surprising) right at the first   &quot;&lt;<span class="" style>md</span>: &quot;  element.</div>
<div style><br></div><div style>So 2 questions:</div><div style><br></div><div style>We&#39;re using the supplied tools (<span class="" style>keygen</span>.sh, <span class="" style>metagen</span>.sh) to create <span class="" style>metadata</span> files for new customers (who appear as a different path in our application tree). We want to add the customer endpoints and <span class="" style>entityID&#39;s</span> to the main <span class="" style>metadata</span> file that we publish. We know we have to care/craft/adjust/edit our <span class="" style>metadata</span>. Clearly the supplied tools are just a starting point, but what guides to people use to make sure the XML is correct for Shibboleth <span class="" style>IdP&#39;s</span> to &quot;consume.&quot; Is there a &quot;generic <span class="" style>metadata</span> file&quot; or documented guide that we can refer to for this type of additional meta?</div>
<div style><br></div><div style>2)  Would just stripping off the &quot; &lt;<span class="" style>md</span>: .. &lt;/<span class="" style>md</span> pairs be enough to correct the problem? Meaning that only one pair of &lt;<span class="" style>md</span>:<span class="" style>EntityDescriptor</span>&gt;...&lt;/<span class="" style>md</span>:<span class="" style>EntityDescriptor</span>&gt; is allowed and subsequent lines cannot have the &lt;<span class="" style>md</span>: .. &lt;/<span class="" style>md</span>: notation.</div>
<div style><br></div><div style><br></div><div style>-- <span class="" style>RGS</span></div><div><div><br>==================================<br>Roy G. Specter<br><a href="mailto:roygspectech8@gmail.com" target="_blank">roygspectech8@gmail.com</a><br>
========================================<br></div>
</div></div>