<div dir="ltr"><div>Thank you for the information, Scott.</div><div><br></div><div>Cathy</div><div><br></div><div><br></div></div><div class="gmail_extra"><br><div class="gmail_quote">On Sat, Jul 22, 2017 at 9:00 AM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span>On 7/21/17, 5:53 PM, "users on behalf of Cathy Scott" <<a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a> on behalf of <a href="mailto:cathystill@gmail.com">cathystill@gmail.com</a>> wrote:<br>
<br>
> The IdP metadata does not include <shibmd:Scope>. In fact, on closer inspection, their metadata looks very different what I've<br>
> seen before. Below is the first part of their metadata.<br>
<br>
</span>That's just a signature.<br>
<span><br>
> Can you tell me what I need to request instead of what they have provided.<br>
<br>
</span>If it's a higher education institution in the US, you should ask them to join InCommon, and then obtain their metadata from there, in an automated and secure fashion. That's how Shibboleth is designed to work. InCommon also curates the Scope extension for you.<br>
<br>
If you want to do it yourself, then you can find examples of metadata all over, and the InCommon feed itself includes hundreds of examples, all with Scope extensions. I would not do it yourself.<br>
<span class="HOEnZb"><font color="#888888"><br>
-- Scott<br>
</font></span><div class="HOEnZb"><div class="h5"><br>
<br>
<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br>
</div></div></blockquote></div><br></div>