<div dir="ltr"><div>My apologies. I misspoke. I do have a single entityID but with many applicationIDs per entityID. So yes, I have a lot of endpoints in that one entity's role. At what point should I start to be concerned and push on my IdP to enable skipEndpointValidationWhenSigned? 1,000? 10,000? Does the IdP process this list on each incoming request? </div><div><br></div><div><br></div></div><div class="gmail_extra"><br><div class="gmail_quote">On Sun, Apr 10, 2016 at 1:05 PM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">> I don't understand "each SSO role in metadata would not need a lot of<br>
> endpoints".<br>
<br>
</span>You said you were using a separate entityID per application. If that's true, then what I said stands, you would have a handful of endpoints.<br>
<br>
If you were combining a bunch of applications under one entityID, then indeed you would have a lot of endpoints in that one entity's role.<br>
<div class="HOEnZb"><div class="h5"><br>
-- Scott<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br></div>