<div dir="ltr"><div dir="ltr">I think the ones that sent metadata with the same EntityID didn't really know how to configure their service in this cloud product.<div>For the one that came with a unique Entity ID, at least we have something to go on to recognize the relying party. But I still can't say I am comfortable with this.</div><div>Good idea to bring it up with PingOne support.</div><div><br></div><div>Joanne</div><div><br><input name="virtru-metadata" type="hidden" value="{"email-policy":{"state":"closed","expirationUnit":"days","disableCopyPaste":false,"disablePrint":false,"disableForwarding":false,"enableNoauth":false,"persistentProtection":false,"expandedWatermarking":false,"expires":false,"isManaged":false},"attachments":{},"compose-id":"6","compose-window":{"secure":false}}"><div><br></div></div></div><br><div class="gmail_quote" style=""><div dir="ltr" class="gmail_attr">On Tue, Jan 28, 2020 at 12:49 PM Peter Schober <<a href="mailto:peter.schober@univie.ac.at">peter.schober@univie.ac.at</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">* Schwendner, Joanne <<a href="mailto:joanne_schwendner@brown.edu" target="_blank">joanne_schwendner@brown.edu</a>> [2020-01-28 18:01]:<br>
> Recently we have had several different vendors present us with the same<br>
> metadata that they generated from this product -- the VERY SAME for all<br>
> vendors. Apparently the SP metadata they get when they set up an<br>
> integration uses the very same ACS endpoints and logout endpoints, and the<br>
> very same signing/encryption cert. A couple even had the same Entity ID.<br>
> (I turned those back.)<br>
<br>
Well, with endpoints, keys and entityIDs being the same that just<br>
tells me in no uncertain terms it's just a single SP. Which would be<br>
fine as long as the policy requirements (attribute release, strong<br>
authentication, etc.) for everything behind that one SP were<br>
sufficiently similar -- and of course the SP doesn't run into trouble<br>
tracking just to what service I actually wanted to log in at any given<br>
point.<br>
<br>
I'm guessing the first condition may or may not be satisfied across<br>
the products having chosen this SAML outsourcing service. The latter<br>
condition -- the SP itself being fine with it -- already seems to have<br>
failed since you wrote:<br>
<br>
> PingOne sorts them out using that Entity ID, and directs them to the<br>
> correct tenant.<br>
<br>
So if they confuse themselfs by allowing duplicate entityIDs among<br>
their tenants, well, nothing good can come from that.<br>
<br>
-peter<br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div></div>