<div dir="ltr"><div dir="ltr"><br></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Fri, Jul 9, 2021 at 11:57 AM Peter Schober <<a href="mailto:peter.schober@univie.ac.at">peter.schober@univie.ac.at</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">* <a href="mailto:vadud3@gmail.com" target="_blank">vadud3@gmail.com</a> <<a href="mailto:vadud3@gmail.com" target="_blank">vadud3@gmail.com</a>> [2021-07-09 16:56]:<br>
> I compared the metadata of<br>
> <a href="https://server.example.org/Shibboleth.sso/Metadata" rel="noreferrer" target="_blank">https://server.example.org/Shibboleth.sso/Metadata</a> with<br>
> <a href="https://node1.example.org/Shibboleth.sso/Metadata" rel="noreferrer" target="_blank">https://node1.example.org/Shibboleth.sso/Metadata</a> and they both have the<br>
> same<br>
> entityID <a href="https://server.example.org" rel="noreferrer" target="_blank">https://server.example.org</a>.<br>
> <br>
> However, the Location for <a href="http://server.example.org" rel="noreferrer" target="_blank">server.example.org</a> is <a href="https://server.example.org" rel="noreferrer" target="_blank">https://server.example.org</a><br>
> and for <a href="http://node1.example.org" rel="noreferrer" target="_blank">node1.example.org</a> is <a href="https://node1.example.org" rel="noreferrer" target="_blank">https://node1.example.org</a><br>
> <br>
> Does that make sense of the same entityID for both? I can then send the<br>
> metadata from node1 to the IdP admin team.<br>
<br>
If you have decided that both servers/vhosts/whetever are in fact one<br>
thing (or rather, do not need to be told apart by any IDPs for local<br>
policy decisions) -- see item 3 from my earlier reply -- you can give<br>
them both the same entityID (and also key pair), no problem.<br>
<br>
But there the software on either server doesn't know that there's the<br>
other side so none of the tools on either side will give you the<br>
complete metadata automatically. I.e., you'd have to assemle the<br>
metadata to give to the IDP:<br>
* One entityID (same on both servers)<br>
* One keypair (same on both servers)<br>
* The relevant ACS URL (HTTP-POST at least) *for* *each* server/host,<br>
  with a unique index XML attribute (index="0" for one, index="1" for<br>
  the other, for example).<br>
<br>
I.e.:<br>
<br>
1. Make the key pair used for SAML the same on both servers.<br>
2. Generate metadata for one of the servers<br>
3. Amend that metadata by hand with the ACS URL for the other server/s<br>
4. Provide amended metadata to the IDP to use.<br>
<br></blockquote><div><br></div><div>EntityNaming under CONCEPTS space aligns with your suggestion of being a unique entity.</div><div>I will modify the enitityID for the node1 vhost and send it over to IDP. </div><div><br></div><div>Thanks a lot!</div><div>Asif</div><div><br></div><div><br></div><div> </div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
-peter<br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div><br clear="all"><div><br></div>-- <br><div dir="ltr" class="gmail_signature">Asif Iqbal<br>PGP Key: 0xE62693C5 KeyServer: <a href="http://pgp.mit.edu" target="_blank">pgp.mit.edu</a><br>A: Because it messes up the order in which people normally read text.<br>Q: Why is top-posting such a bad thing?<br><br></div></div>