<div dir="ltr">Thank you very much Scott</div><div class="gmail_extra"><br><br><div class="gmail_quote">On Wed, Jul 23, 2014 at 5:23 PM, Cantor, Scott <span dir="ltr">&lt;<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>&gt;</span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div class="">On 7/23/14, 9:38 AM, &quot;Stefano Zanmarchi&quot; &lt;<a href="mailto:zanmarchi@gmail.com">zanmarchi@gmail.com</a>&gt; wrote:<br>

<br>
&gt;on our IdP&#39;s metadata we have currently configured two SPs<br>
&gt;(&quot;<a href="https://hostA/shibboleth" target="_blank">https://hostA/shibboleth</a>&quot;<br>
&gt;and &quot;<a href="https://hostB/shibboleth" target="_blank">https://hostB/shibboleth</a>&quot;) which share a same<br>
&gt;AssertionConsumerService entry.<br>
&gt;It&#39;s working, I&#39;m not now evaluating if this is the best solution and why<br>
&gt;it has been done,<br>
&gt;my concern is about formal correctness. I&#39;m afraid that it&#39;s not and that<br>
&gt;sooner<br>
&gt;or later we could run into problems. Is this solution fine or should we<br>
&gt;avoid it?<br>
<br>
</div>I can&#39;t tell you about what other implementations do, but it&#39;s legal in<br>
SAML and it works fine with Shibboleth (aside from the fact that with the<br>
SP itself, you can&#39;t have a single installation of the SP handle one<br>
endpoint without it mapping to one and only one applicationId and thus<br>
entityID).<br>
<span class="HOEnZb"><font color="#888888"><br>
-- Scott<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</font></span></blockquote></div><br></div>