<div dir="ltr">I updated all the URLs in the IdP metadata, so they were correct, and changed the entityID in idp.properties and the metadata (it's only properly paired up with one SP anyway, Canvas, and their implementation of SAML lets me tell it where to get the metadata from - so an XML file on an HTTPS-fronted server of ours, which it knows about).<div>I checked the IdP logs too, no sign of errors there (or of it being hit to process any attempt).</div></div><div class="gmail_extra"><br><div class="gmail_quote">On Wed, Jun 6, 2018 at 3:58 PM, Peter Schober <span dir="ltr"><<a href="mailto:peter.schober@univie.ac.at" target="_blank">peter.schober@univie.ac.at</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">* HCUK eLearning <<a href="mailto:daveperryatwork@gmail.com">daveperryatwork@gmail.com</a>> [2018-06-06 16:33]:<br>
<span class="">> We run Jetty 9.3 for our live and test IdPs. I've changed the URL for our<br>
> test one (moving to a different subdomain, forced by our reverse proxy<br>
> managers), and given Jetty the new HTTPS certificate - it seems to load<br>
> fine.<br>
<br>
</span>You don't mention what else you've changed. Changing "the URL" for an<br>
IDP also means having to change all the SPs it federates with.<br>
That may come down to providing the with updated SAML 2.0 Metadata, or<br>
it may involve manual work where metadata is not being used.<br>
<span class="HOEnZb"><font color="#888888"><br>
-peter<br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/<wbr>confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br>
</font></span></blockquote></div><br></div>