<div dir="ltr"><div><div><div><div>Scott, <br><br></div>Thank you for your reply. <br><br>> Top of mind is stop playing these games with URLs. I have no idea why 
you think it's necessary for the IdP to live at different virtual hosts,
 but that's just creating problems.<br><br></div>I would like to avoid these games more than anybody else, but as many here, we are left no choice.<br><br>> unless you supply different metadata based on the vhost. The Shibboleth 
SP certainly can handle that, but it's hardly productive work.<br><br></div><div>Can the same thing be done for the IdP (ver. 3.1.2)? I mean supplying (or rather choosing) different SP's metadata depending on the host name of the access URL? If yes, could somebody give me some pointers on where to look at?<br></div><div><div class=""><div id=":s6" class="" tabindex="0"><br></div></div></div>--<br><br>By the way, I plan to use multiple IdP's entityIDs and use IdP Discovery to make the correct selection of the IdP on the SP side. <br><br></div>Thanks!<br><div><br><br><div><div><br></div></div></div></div><div class="gmail_extra"><br><div class="gmail_quote">On Tue, Feb 2, 2016 at 12:09 AM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">> Option 1. Relative urls for the endpoints in metadata for both IdP and SP.<br>
><br>
> Is this possible / allowed at all from SAML perspective? Are there any issues I<br>
> need to worry about?<br>
<br>
</span>Not allowed and not supported.<br>
<span class=""><br>
> Option 2. Hack into SP's and IdP's assertions creation logic in order to set<br>
> correct URL for HTTP-POST bindings (we only use post bindings)<br>
<br>
</span>It's the SP implementation responsible for properly expressing the URL it needs used, and the IdP should simply enforce that via metadata. Your problem is a broken SP, or a broken configuration of an SP.<br>
<br>
A Shibboleth SP, certainly, will do the right thing if the web server is properly configured.<br>
<span class=""><br>
> Any ideas how I can solve this problem?<br>
<br>
</span>Top of mind is stop playing these games with URLs. I have no idea why you think it's necessary for the IdP to live at different virtual hosts, but that's just creating problems. You cannot, with one entityID, dictate which SSO endpoint an SP will use unless you supply different metadata based on the vhost. The Shibboleth SP certainly can handle that, but it's hardly productive work.<br>
<span class="HOEnZb"><font color="#888888"><br>
-- Scott<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</font></span></blockquote></div><br></div>