<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class="">
Those are the same "scopes" (which typically match DNS domains) that you use for the eduPersonScopedAffiliation attribute.
<div class=""><br class="">
</div>
<div class="">For example, we have one IdP that handles multiple universities.</div>
<div class=""><br class="">
</div>
<div class="">We have the following scopes: <a href="http://unt.edu" class="">unt.edu</a>, untdallas.edu, unthsc.edu.</div>
<div class=""><br class="">
</div>
<div class="">Our eduPersonScopedAffiliation attribute may return values like the following:</div>
<div class=""><br class="">
</div>
<div class=""><a href="mailto:student@unt.edu" class="">student@unt.edu</a></div>
<div class=""><a href="mailto:staff@untdallas.edu" class="">staff@untdallas.edu</a></div>
<div class=""><a href="mailto:staff@unthsc.edu" class="">staff@unthsc.edu</a></div>
<div class=""><a href="mailto:faculty@untdallas.edu" class="">faculty@untdallas.edu</a></div>
<div class=""><br class="">
</div>
<div class=""><br class="">
</div>
<div class="">The "Scope" XML element (which may be repeated multiple times) in the extensions section of the IdP metadata lists scopes for which the IdP is authoritative. In other words, it says which scopes are owned by the IdP.</div>
<div class=""><br class="">
</div>
<div class="">If the IdP is authoritative for scopes <a href="http://unt.edu" class="">unt.edu</a>, unthsc.edu, and untdallas.edu, but sends an eduPersonScopedAffiliation value of student@mit.edu, that is clearly wrong and the SP should ignore the incorrectly
scoped value. The Shibboleth SP does ignore incorrectly scoped values.</div>
<div class=""><br class="">
</div>
<div class="">
<div class="">I hope that helps to explain the concept of scopes.</div>
<div class=""><br class="">
</div>
</div>
<div class="">Yancey Yeargan</div>
<div class="">University of North Texas System</div>
<div class=""><br class="">
</div>
<div class=""><br class="">
<div>
<blockquote type="cite" class="">
<div class="">On Mar 5, 2020, at 8:48 AM, Mohamed Lrhazi <<a href="mailto:lrhazi@cua.edu" class="">lrhazi@cua.edu</a>> wrote:</div>
<br class="Apple-interchange-newline">
<div class="">
<div dir="ltr" class="">Hello,
<div class=""><br class="">
</div>
<div class="">I have setup our IdP for a couple of years now, and have been happily adding new SPs every now and then, and everyone is happy :)</div>
<div class=""><br class="">
</div>
<div class="">Today am trying to add an SP and they complain that our metadata has this example section in it:</div>
<div class=""><br class="">
</div>
<div class=""><EntityDescriptor....<br class="">
</div>
<div class=""><IDPSSODescriptor...<br class="">
</div>
<div class=""> <Extensions><br class="">
<shibmd:Scope regexp="false"><a href="https://nam04.safelinks.protection.outlook.com/?url=http%3A%2F%2Fexample.org%2F&data=02%7C01%7CYancey.Yeargan%40untsystem.edu%7Cc6e801e3b87d4462c9a408d7c1146450%7C70de199207c6480fa318a1afcba03983%7C0%7C1%7C637190165637626301&sdata=dRHWQky7svlJPl0E8xBX%2FIT71e37kiCsaHx%2BUIPJylM%3D&reserved=0" originalsrc="http://example.org/" shash="F1d0shJYIsIgE6C12YO/Zy9HRCr65vVl/9HyhttgLJUn0I+4bj0WbvDZIvsS7buaxgAIKXJPgRcs+rRcsuixfwQCG02moP7VKPHn6rCRXpD3sh/CAy9UaFzeVOuYc1Rhqn4zLQ5Xtv9OfiWAAc8ZSo1HfBGd+w6Pw5+vTpbmhac=" class="">example.org</a></shibmd:Scope><br class="">
</div>
<div class=""><br class="">
</div>
<div class=""></Extensions><br class="">
</div>
<div class="">...</div>
<div class=""><br class="">
</div>
<div class="">I obviously left the example from the sample metadata file... and never got to learn about scopes at all....</div>
<div class=""><br class="">
</div>
<div class="">Anyone has a link to some high level document I could read to figure what would the implications be if I were to: try and fix this... Can I just remove the Extensions/ Scope element from my IdP metadata, or should I change the scope to be one
of our DNS domain names, what should my scope be? and do I need to have one at all? I guess maybe mine has been
<a href="https://nam04.safelinks.protection.outlook.com/?url=http%3A%2F%2Fexample.org%2F&data=02%7C01%7CYancey.Yeargan%40untsystem.edu%7Cc6e801e3b87d4462c9a408d7c1146450%7C70de199207c6480fa318a1afcba03983%7C0%7C1%7C637190165637636291&sdata=Phi%2BIenKc4iv36KKW6Eb1YytDcaypa3vYi3HaLLl15s%3D&reserved=0" originalsrc="http://example.org/" shash="YVI/1zEdKR0SmF7N4INcBFv2X1rBsGChmyHWkyOFJNlv4OMII45eaZAYD2LAvWH3v4LkAuHxjJ6WTYROZkeV6qMlYjRO9ZuQQJQWqDuVc6eedKzv4rOtkj0HfKhAfvBXR6ZdodHcTI4feknGN+VDr32iIfMw4lgNHZ5WisHWBEI=" class="">
example.org</a> all these years! is that bad? :)</div>
<div class=""><br class="">
</div>
<div class="">Thanks a lot,</div>
<div class="">Mohamed.</div>
<div class=""><br class="">
</div>
<div class=""><br class="">
</div>
<div class=""><br class="">
</div>
<div class=""><br class="">
</div>
</div>
-- <br class="">
For Consortium Member technical support, see <a href="https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwiki.shibboleth.net%2Fconfluence%2Fx%2FcoFAAg&data=02%7C01%7CYancey.Yeargan%40untsystem.edu%7Cc6e801e3b87d4462c9a408d7c1146450%7C70de199207c6480fa318a1afcba03983%7C0%7C0%7C637190165637656279&sdata=lyqPKmG5HH8%2F3JF9WmKqYSyECS0nTdoU6P69wO6LDcw%3D&reserved=0" class="">
https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwiki.shibboleth.net%2Fconfluence%2Fx%2FcoFAAg&data=02%7C01%7CYancey.Yeargan%40untsystem.edu%7Cc6e801e3b87d4462c9a408d7c1146450%7C70de199207c6480fa318a1afcba03983%7C0%7C0%7C637190165637656279&sdata=lyqPKmG5HH8%2F3JF9WmKqYSyECS0nTdoU6P69wO6LDcw%3D&reserved=0</a><br class="">
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" class="">
users-unsubscribe@shibboleth.net</a></div>
</blockquote>
</div>
<br class="">
</div>
</body>
</html>