<div dir="ltr"><br><div class="gmail_extra"><br><div class="gmail_quote">On Sat, Nov 7, 2015 at 5:48 PM, Tom Scavo <span dir="ltr"><<a href="mailto:trscavo@gmail.com" target="_blank">trscavo@gmail.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">This is not a shib question but...<br>
<span class=""><br>
On Sat, Nov 7, 2015 at 10:54 AM, Phil Lello <<a href="mailto:phil@dunlop-lello.uk">phil@dunlop-lello.uk</a>> wrote:<br>
><br>
</span><span class=""><br>
> is it<br>
> sufficient to populate the AssertionConsumerServiceURL for each SP, or would<br>
> there need to be a common ACS to proxy assertions (after adjusting payload<br>
> as necessary and re-signing/re-encrypting messages)?<br>
<br>
</span>The AssertionConsumerService endpoint is indexed, so you can add as<br>
many as you like, each with its own unique index value.<br>
<span class="HOEnZb"><font color="#888888"><br></font></span></blockquote><div>Perhaps I should have specified I'm talking about the AssertionConsumerService in the AuthnRequest from the SP, and whether or not the Shibboleth IdP will respect use value in the request if it isn't present in the metadata the IdP holds for a given SP.<br><br></div></div><br></div></div>