<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<style type="text/css" style="display:none;"><!-- P {margin-top:0;margin-bottom:0;} --></style>
</head>
<body dir="ltr">
<div id="divtagdefaultwrapper" style="font-size:12pt;color:#000000;font-family:Calibri,Helvetica,sans-serif;" dir="ltr">
<p>Chanda,</p>
<p><br>
</p>
<p>He just means that your identity layer should fit your application layer.  Shibboleth does not dictate the requirements to your application.</p>
<p><br>
</p>
<p>If your application is spread across many hosts, then you're reinventing an SSO protocol.  Just protect the services where they are if you can.  Fewer hosts is easier in my experience.</p>
<p><br>
</p>
<p>Hope this helps,</p>
<p>Nate.</p>
</div>
<hr style="display:inline-block;width:98%" tabindex="-1">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Chanda Banda <chandabnd727@googlemail.com><br>
<b>Sent:</b> Thursday, November 23, 2017 8:54:18 AM<br>
<b>To:</b> Shib Users<br>
<b>Subject:</b> Re: Multiple domains and Shibboleth</font>
<div> </div>
</div>
<div>
<div dir="ltr">
<div>
<div>Many thanks for your reply. <br>
<br>
</div>
I understand that if I have <a href="http://abc.com">abc.com</a> and <a href="http://def.com">
def.com</a> on Server1 and <a href="http://xyz.com">xyz.com</a> <br>
</div>
<div>on Server2 then I need to install Shibboleth on both servers and the installation
<br>
</div>
<div>on Server1 will handle both the domains on that server.</div>
<div><br>
</div>
<div>You say "<i>Don't invent new FQDNs to protect content on existing FQDNs.</i>".</div>
<div>I presume by that you mean that i should have <a href="http://sb.abc.com">sb.abc.com</a> and
<a href="http://sb.def.com">sb.def.com</a></div>
<div>but not <a href="http://sb.some-new-domain.com">sb.some-new-domain.com</a>?</div>
<div><br>
</div>
<div>Am I right?</div>
<div><br>
</div>
<div>Thanks.<br>
</div>
</div>
<div class="x_gmail_extra"><br>
<div class="x_gmail_quote">On Tue, Nov 21, 2017 at 6:32 PM, Peter Schober <span dir="ltr">
<<a href="mailto:peter.schober@univie.ac.at" target="_blank">peter.schober@univie.ac.at</a>></span> wrote:<br>
<blockquote class="x_gmail_quote" style="margin:0 0 0 .8ex; border-left:1px #ccc solid; padding-left:1ex">
* Chanda Banda <<a href="mailto:chandabnd727@googlemail.com">chandabnd727@googlemail.com</a>> [2017-11-21 19:26]:<br>
> What is the best/recommended way to implement Shibboleth for my scenario?<br>
<br>
One you haven't listed yet:<br>
<br>
*Option5*<br>
<br>
Make sure Shibboleth is installed on any web server that hosts content<br>
that needs to be protected. Then enable it for all vhosts / resources<br>
as needed.<br>
<br>
Don't invent new FQDNs to protect content on existing FQDNs.<br>
<br>
See also <a href="http://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPOneMany" rel="noreferrer" target="_blank">
wiki.shibboleth.net/<wbr>confluence/display/SHIB2/<wbr>NativeSPOneMany</a><br>
<span class="x_HOEnZb"><font color="#888888"><br>
-peter<br>
--<br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">
https://wiki.shibboleth.net/<wbr>confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">
users-unsubscribe@shibboleth.<wbr>net</a><br>
</font></span></blockquote>
</div>
<br>
</div>
</div>
</body>
</html>