<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta content="text/html; charset=utf-8">
<meta name="Title" content="">
<meta name="Keywords" content="">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style>
<!--
@font-face
{font-family:"\FF2D \FF33 \660E \671D "}
@font-face
{font-family:"Cambria Math"}
@font-face
{font-family:Calibri}
@font-face
{font-family:"Trajan Pro"}
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:12.0pt;
font-family:Calibri}
a:link, span.MsoHyperlink
{color:#0563C1;
text-decoration:underline}
a:visited, span.MsoHyperlinkFollowed
{color:#954F72;
text-decoration:underline}
span.EmailStyle17
{font-family:Calibri;
color:windowtext}
span.msoIns
{text-decoration:underline;
color:teal}
.MsoChpDefault
{font-family:Calibri}
@page WordSection1
{margin:1.0in 1.0in 1.0in 1.0in}
div.WordSection1
{}
-->
</style>
</head>
<body lang="EN-US" link="#0563C1" vlink="#954F72">
<span style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:11pt; color:black">Hi Jeff-<br>
<br>
In ldap.properties, the ldap URL can be a space - delimited list with multiple servers.<br>
<br>
RE: Artifact, just don't include those endpoints in your metadata.<br>
<br>
Hope that answers your questions...<br>
<br>
<br>
<br>
<span style="color:black">-----Original Message----- <br>
<b>From:</b> Reynolds, Jeffrey [JReynolds@utdallas.edu]<br>
<b>Received:</b> Thursday, 19 May 2016, 14:59<br>
<b>To:</b> Shib Users [users@shibboleth.net]<br>
<b>Subject:</b> SAML2 Support Listed In Metadata<br>
<br>
</span></span>
<div>
<div class="WordSection1">
<p class="MsoNormal"><span style="font-size:11.0pt">Hi everybody,</span></p>
<p class="MsoNormal"><span style="font-size:11.0pt"> </span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">I’ve got two questions, one of which I probably already know the answer to (though having confirmation would be helpful).
</span></p>
<p class="MsoNormal"><span style="font-size:11.0pt"> </span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">Our institution is in the process of upgrading from IdP v2 to v3, and I had a question about configuring multiple LDAP data connectors. I’ve seen that one difference between v2 and v3 is that there is an
ldap.properties file which appears to expose more of the advanced LDAP options. But this setup seems to only allow for a single LDAP data connector (note I’m trying to connect to two different directories, not multiple nodes of a single directory). I’m assuming
that I can define DataConnector elements in v3 like I could in V2 (ignoring the ldap.properites file if I specify those values directly in the attribute-resolver), but is this the intended way to do this, or is there another option to either define multiple
servers in a single properties file, or have multiple files?</span></p>
<p class="MsoNormal"><span style="font-size:11.0pt"> </span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">Second, and I think I know the answer to this but I have to ask, if we declare that we support “urn:oasis:names:tc:SAML:2.0:protocol” in our metadata file does this mean we also have to support artifact resolution?
We currently don’t have any service providers that utilize artifact resolution, and we would like to officially drop support of it, at least until we get a chance to but some more planning into our load balancing architecture. Of course, one of the objectives
of this upgrade is to clean up our deployment, so if it’s a requirement we’ll definitely work it in.</span></p>
<p class="MsoNormal"><span style="font-size:11.0pt"> </span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">Thanks for any guidance on these issues. Though I’m not as knowledgeable in Shibboleth and SAML as I’d like to be, I’m looking forward to this upgrade as an opportunity to become more compliant with the standards
and have a better working setup.</span></p>
<p class="MsoNormal"><span style="font-size:11.0pt"> </span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">Much obliged,</span></p>
<p class="MsoNormal"><span style="font-size:11.0pt"> </span></p>
<p class="MsoNormal"><b><span style="font-size:11.0pt; font-family:"Trajan Pro","serif"; color:black">Jeff Reynolds</span></b><span style="font-size:11.0pt; font-family:"Times New Roman"; color:black"></span></p>
<div>
<p class="MsoNormal"><span style="font-size:10.0pt; font-family:"Times New Roman"; color:#B94610">Senior Information Security Analyst</span><span style="font-size:11.0pt; font-family:"Times New Roman"; color:black"></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt; font-family:"Times New Roman"; color:#B94610">972-883-6828 | <a href="mailto:jreynolds@utdallas.edu"><span style="color:#B94610">jreynolds@utdallas.edu</span></a></span><span style="font-size:11.0pt; font-family:"Times New Roman"; color:black"></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt; font-family:"Times New Roman"; color:#B94610"><a href="http://secure-web.cisco.com/1afCCmPALdg8YuA9L0O0t06wOtg6oUwOf27frULVxl6D4hz3F7rZiqOAtTpcdN-LobE-ckT8015ydA9aER611c1CaVtBbMu4_EzfGwuF8zFkhgoZM9QwUYSqIy3pOsTWpensz7zUmLNEusIrRmGqLcgQcptLIzVCi8_pjvs1ZkDmomfcOt0-qeYGcJSbQbyeM/http%3A%2F%2Fwww.utdallas.edu%2Finfosecurity%2F"><span style="color:#B94610">Information
Security Office</span></a></span><span style="font-size:11.0pt; font-family:"Times New Roman"; color:black"></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt; font-family:"Times New Roman"; color:black"><a href="http://secure-web.cisco.com/1Cpl8ttBT6ZGunfGnpHes_P09cbe-u9TknUQoTtH8s3Ib-Ksf7gQk5OG94tS227GNQbJLBle-3By0cQFZqCpbyjy0R5KsrPm_kyk0Q2ThKqeUPqC8h8o5S7XzFjmiqcpFGbFJZYFaOEBfrw98cKcOqV5QIX1jYsZU39sP_RwaCn7puMfiQYtPpGdOe3HFtHqX/http%3A%2F%2Fwww.utdallas.edu%2F"><span style="color:#B94610">The
University of Texas at Dallas</span></a></span><span style="font-size:11.0pt; font-family:"Times New Roman"; color:black"></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt; font-family:"Times New Roman"; color:black"><a href="http://secure-web.cisco.com/1szYsJ4dNTeYEjpBFxN7WspaYjrR3ILWtiKtLTUNMu_zh_MDZZy2vcPCK-nj_pPyvg2lhG-lX3dz1cGHhoGnRxvq5WBK81YXv7CMTwxa28zxJ_J87QKVu6IThqP-wobIbl6adOD-Iaal04Q4v5lqpOopinaROydDyGogSKFgtXcbqa3Sv5mU_CcLY2LvE5K-e/http%3A%2F%2Futdallas.parature.com%2F"></a></span><a href="http://secure-web.cisco.com/1szYsJ4dNTeYEjpBFxN7WspaYjrR3ILWtiKtLTUNMu_zh_MDZZy2vcPCK-nj_pPyvg2lhG-lX3dz1cGHhoGnRxvq5WBK81YXv7CMTwxa28zxJ_J87QKVu6IThqP-wobIbl6adOD-Iaal04Q4v5lqpOopinaROydDyGogSKFgtXcbqa3Sv5mU_CcLY2LvE5K-e/http%3A%2F%2Futdallas.parature.com%2F"><img border="0" width="180" height="52" src="file://localhost/Users/jjr140030/Library/Containers/com.microsoft.Outlook/Data/Library/Caches/Signatures/signature_212653709" align="left" hspace="12" title=""></a><a href="http://secure-web.cisco.com/1szYsJ4dNTeYEjpBFxN7WspaYjrR3ILWtiKtLTUNMu_zh_MDZZy2vcPCK-nj_pPyvg2lhG-lX3dz1cGHhoGnRxvq5WBK81YXv7CMTwxa28zxJ_J87QKVu6IThqP-wobIbl6adOD-Iaal04Q4v5lqpOopinaROydDyGogSKFgtXcbqa3Sv5mU_CcLY2LvE5K-e/http%3A%2F%2Futdallas.parature.com%2F"></a><span style="font-size:11.0pt; font-family:"Times New Roman"; color:black"></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:10.5pt; color:black"> </span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:10.5pt; color:black"> </span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:10.5pt; color:black"> </span></p>
</div>
<p class="MsoNormal"><span style="font-size:11.0pt"> </span></p>
<p class="MsoNormal"><span style="font-size:11.0pt"> </span></p>
</div>
</div>
</body>
</html>