<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<!--[if !mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]--><style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:"Yu Gothic";
        panose-1:2 11 4 0 0 0 0 0 0 0;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Verdana;
        panose-1:2 11 6 4 3 5 4 4 2 4;}
@font-face
        {font-family:Cambria;
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:"Arial Bold";
        panose-1:2 11 7 4 2 2 2 2 2 4;}
@font-face
        {font-family:"\@Yu Gothic";
        panose-1:2 11 4 0 0 0 0 0 0 0;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        font-size:10.0pt;
        font-family:"Verdana",sans-serif;
        color:#4864A7;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:#CE3345;
        text-decoration:underline;}
span.EmailStyle22
        {mso-style-type:personal-reply;
        font-family:"Calibri",sans-serif;
        color:#1F497D;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body bgcolor="white" background="cid:image001.gif@01D91E87.4FE8B7D0" lang="EN-US" link="#CE3345" vlink="#A43ACE" style="word-wrap:break-word">
<img src="cid:image001.gif@01D91E87.4FE8B7D0" v:src="cid:image001.gif@01D91E87.4FE8B7D0" v:shapes="_x0000_Mail" width="0" height="0" class="shape" style="display:none;width:0;height:0">
<div class="WordSection1">
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">Thank you for this—very helpful. I’ll find an entry point for the vendor.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">-Florian<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:windowtext">From:</span></b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:windowtext"> Koren, Meshna (ELS-AMS) <M.Koren@elsevier.com>
<br>
<b>Sent:</b> Friday, December 23, 2022 10:40 AM<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Cc:</b> Florian Lengyel <Florian.Lengyel@cuny.edu><br>
<b>Subject:</b> RE: Education vendor SSO configuration requires separate IDP entityIDs for each SP!<o:p></o:p></span></p>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#595959">Hi Florian,<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#595959"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#595959">What a great question you've raised.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#595959"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#595959">As another SP I also think this is a bit of unwanted behaviour. For federated authn to remain scalabale an entityID should represent a meaningful entity, something
 that a human user can relate to, and not 'an app' that's essentially just a connection between two entities or a configuration set; which is what Okta does. Unfortunately that's indeed not a rule or spelled out anywhere… but it can be seen when one spends
 5 minutes looking in the metadata with REFEDS explorer tool:<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#595959"><a href="https://urldefense.proofpoint.com/v2/url?u=https-3A__met.refeds.org_&d=DwMFAg&c=mRWFL96tuqj9V0Jjj4h40ddo0XsmttALwKjAEOCyUjY&r=w05DwAF0P7ofwV4XZt1zDuW3aSHj2h4ep8o8gzwYbJo&m=jqvkIJB1NySchJN98MdlTIL-w2sMGBQoJzDm7Fg9kbkMGvxMmv1KljUsoQsT9IKp&s=yL-gprwy2cCWlhQFcDeYa9uRZLIUeJEptN-bXwjR9fE&e=">https://met.refeds.org/</a><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#595959">where each entityIDs also has a recognizable display name.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#595959"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#595959">My suggestion would be to ask the SP to take time and review
<i>AARC blueprint architecture</i>:<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#595959"><a href="https://urldefense.proofpoint.com/v2/url?u=https-3A__aarc-2Dcommunity.org_architecture_&d=DwMFAg&c=mRWFL96tuqj9V0Jjj4h40ddo0XsmttALwKjAEOCyUjY&r=w05DwAF0P7ofwV4XZt1zDuW3aSHj2h4ep8o8gzwYbJo&m=jqvkIJB1NySchJN98MdlTIL-w2sMGBQoJzDm7Fg9kbkMGvxMmv1KljUsoQsT9IKp&s=1Gryex_CKeQcSKMekhKQ8MFiqC62C_jIXkuhZnbBCow&e=">https://aarc-community.org/architecture/</a><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#595959">(and the metadata explorer tool) with a note that this is how most of academic community uses federated authn today; this system offers a lot of opportunities
 such as Seamless Access etc from which the SP will undoubtedly benefit in more than one way.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#595959"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#595959">I don't know what's the best starting point, though.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#595959"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#595959">Kind regards,<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#595959">Meshna<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#595959"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#595959"><o:p> </o:p></span></p>
<p class="MsoNormal"><b><span lang="EN-GB" style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#595959"><o:p> </o:p></span></b></p>
<p class="MsoNormal"><b><span lang="EN-GB" style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#595959">Meshna Koren</span></b><b><span lang="EN-GB" style="font-size:9.0pt;font-family:"Calibri",sans-serif;color:#595959">
<o:p></o:p></span></b></p>
<p class="MsoNormal"><span lang="EN-GB" style="font-size:9.0pt;font-family:"Calibri",sans-serif;color:#595959"><br>
</span><i><span lang="EN-GB" style="font-size:9.0pt;font-family:"Cambria",serif;color:#595959">Product Manager II<o:p></o:p></span></i></p>
<p class="MsoNormal"><b><i><span lang="EN-GB" style="font-size:9.0pt;font-family:"Cambria",serif;color:#595959">Product Management, Identity<o:p></o:p></span></i></b></p>
<p class="MsoNormal"><b><i><span lang="EN-GB" style="font-size:9.0pt;font-family:"Cambria",serif;color:#1F497D"><o:p> </o:p></span></i></b></p>
<p class="MsoNormal"><b><i><span lang="EN-GB" style="font-size:9.0pt;font-family:"Cambria",serif;color:#E36C0A">Elsevier BV</span></i></b><i><span lang="EN-GB" style="font-size:9.0pt;font-family:"Cambria",serif;color:#1F497D"><o:p></o:p></span></i></p>
<p class="MsoNormal"><i><span lang="NL" style="font-size:9.0pt;font-family:"Cambria",serif;color:#595959">Radarweg 29, Amsterdam 1043 NX, The Netherlands<o:p></o:p></span></i></p>
<p class="MsoNormal"><i><span lang="EN-GB" style="font-size:9.0pt;font-family:"Cambria",serif;color:#1F497D"><a href="mailto:m.koren@elsevier.com"><span lang="NL" style="color:blue">m.koren@elsevier.com</span></a></span></i><i><span lang="NL" style="font-size:9.0pt;font-family:"Cambria",serif;color:#1F497D"><o:p></o:p></span></i></p>
<p class="MsoNormal"><i><span lang="NL" style="font-size:9.0pt;font-family:"Cambria",serif;color:#1F497D"><o:p> </o:p></span></i></p>
<p class="MsoNormal"><i><span lang="EN-GB" style="font-size:9.0pt;font-family:"Cambria",serif;color:#E36C0A">Federated Access - SAML, Shibboleth, Corporate SSO, OpenAthens, Institutional Login<o:p></o:p></span></i></p>
<p class="MsoNormal"><i><span lang="EN-GB" style="font-size:9.0pt;font-family:"Cambria",serif;color:#E36C0A"><o:p> </o:p></span></i></p>
<p class="MsoNormal"><i><span style="font-size:9.0pt;font-family:"Calibri",sans-serif;color:#595959">Elsevier Access Support Center:
<a href="https://urldefense.proofpoint.com/v2/url?u=https-3A__service.elsevier.com_app_home_supporthub_elsevieraccess_&d=DwMFAg&c=mRWFL96tuqj9V0Jjj4h40ddo0XsmttALwKjAEOCyUjY&r=w05DwAF0P7ofwV4XZt1zDuW3aSHj2h4ep8o8gzwYbJo&m=jqvkIJB1NySchJN98MdlTIL-w2sMGBQoJzDm7Fg9kbkMGvxMmv1KljUsoQsT9IKp&s=95pdzqaM-4SOjc8yhQcjk5a48V-kXw4_Rbb6JeJnETo&e=">
<span style="color:blue">https://service.elsevier.com/app/home/supporthub/elsevieraccess/</span></a><o:p></o:p></span></i></p>
<p class="MsoNormal"><i><span style="font-size:9.0pt;font-family:"Calibri",sans-serif;color:#595959">for your questions about which access methods does Elsevier support, how to set them up, how do they work for users...<o:p></o:p></span></i></p>
<p class="MsoNormal"><i><span lang="EN-GB" style="font-size:9.0pt;font-family:"Cambria",serif;color:#E36C0A"><o:p> </o:p></span></i></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#595959"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#595959"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#595959"><o:p> </o:p></span></p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:windowtext">From:</span></b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:windowtext"> users <<a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a>>
<b>On Behalf Of </b>Florian Lengyel via users<br>
<b>Sent:</b> Thursday, December 22, 2022 01:43<br>
<b>To:</b> Shib Users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>><br>
<b>Cc:</b> Florian Lengyel <<a href="mailto:Florian.Lengyel@cuny.edu">Florian.Lengyel@cuny.edu</a>><br>
<b>Subject:</b> RE: Education vendor SSO configuration requires separate IDP entityIDs for each SP!<o:p></o:p></span></p>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<p><strong><span style="font-family:"Calibri",sans-serif;color:black;background:#FF4F00">*** External email: use caution ***</span></strong><o:p></o:p></p>
<p> <o:p></o:p></p>
<div>
<p class="MsoNormal"><span style="color:#1F497D">My suspicion was that this particular service provider was using Okta—this is now confirmed. In my experience,
<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">some SP developers who use Okta have the impression that each SP must have its own distinct IDP metadata—the
<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">metadata cannot be the same.  I was able to disabuse one vendor of this misapprehension. However, the latest vendor<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">has designed an SP that somehow assigns a so-called OPID to the entityID of the IDP (not kidding!), instead of relying an
<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">attribute such as eduPersonScopedAffiliation in the SAML response to the SP—or something sensible.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Scott Cantor’s response was very helpful, by the way. This is something I can send up the flagpole.
<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">I guess he’s seen everything. I’m still capable of being nonplussed—not to mention flabbergasted.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">-F<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:windowtext">From:</span></b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:windowtext"> users <<a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a>>
<b>On Behalf Of </b>Spencer Thomas via users<br>
<b>Sent:</b> Wednesday, December 21, 2022 5:27 PM<br>
<b>To:</b> Shib Users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>><br>
<b>Cc:</b> Spencer Thomas <<a href="mailto:Spencer.Thomas@ithaka.org">Spencer.Thomas@ithaka.org</a>><br>
<b>Subject:</b> Re: Education vendor SSO configuration requires separate IDP entityIDs for each SP!<o:p></o:p></span></p>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<div>
<table class="MsoNormalTable" border="1" cellspacing="4" cellpadding="0" width="100%" style="width:100.0%;background:#C74606">
<tbody>
<tr>
<td style="padding:.75pt .75pt .75pt .75pt">
<p class="MsoNormal" align="center" style="text-align:center"><b><span style="font-size:13.5pt;font-family:"Arial Bold";color:yellow">***ATTENTION:</span></b><span style="font-size:13.5pt;font-family:"Arial Bold";color:yellow">
</span><span style="font-size:12.0pt;font-family:"Arial Bold";color:yellow">This email came from an external source. Do not open attachments or click on links from unknown senders or unexpected emails.***</span><span style="font-size:13.5pt;font-family:"Arial Bold";color:yellow">
</span><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:windowtext"><o:p></o:p></span></p>
</td>
</tr>
</tbody>
</table>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:windowtext"><o:p> </o:p></span></p>
</div>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:windowtext">And when I said eduPersonEntitlement, I actually meant eduPersonScopedAffiliation.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:windowtext"><o:p> </o:p></span></p>
<div>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:windowtext">On 12/21/22, 2:12 PM, "users" <<a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a>> wrote:<o:p></o:p></span></p>
</div>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:windowtext"><br>
<img border="0" width="50" height="50" style="width:.5208in;height:.5208in" id="Picture_x0020_1" src="cid:image001.gif@01D91E87.4FE8B7D0"><o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:windowtext">As a service provider, I can say that we have definitely engineered our SP to accommodate multiple institutions using the same EntityID.
 We obviously require a different attribute, most typically eduPersonEntitlement, to distinguish between those institutions.
</span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:windowtext"> </span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:windowtext">-- </span><o:p></o:p></p>
<div>
<p class="MsoNormal" style="margin-left:.5in"><b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:black">Spencer Thomas<br>
</span></b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:black">Technical Architect </span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:black"><a href="https://urldefense.proofpoint.com/v2/url?u=https-3A__nam11.safelinks.protection.outlook.com_-3Furl-3Dhttps-253A-252F-252Furldefense.proofpoint.com-252Fv2-252Furl-253Fu-253Dhttps-2D3A-5F-5Fwww.ithaka.org-5F-2526d-253DDwMF-2Dg-2526c-253DmRWFL96tuqj9V0Jjj4h40ddo0XsmttALwKjAEOCyUjY-2526r-253Dw05DwAF0P7ofwV4XZt1zDuW3aSHj2h4ep8o8gzwYbJo-2526m-253DFUytUOszF6u1h8HnN-2DDI-5FKv6s8vLU5eCFdhIJBFjVOa-2DJxl0iyomlKsYqEnOpRmE-2526s-253DyA6pvruWzOEpvdkwsi93VD2ROpHBPWlwbuAGWtFbcaY-2526e-253D-26data-3D05-257C01-257CM.Koren-2540elsevier.com-257Cf67c24b06f5a4c37019408dae3b5822a-257C9274ee3f94254109a27f9fb15c10675d-257C0-257C0-257C638072666408236143-257CUnknown-257CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0-253D-257C2000-257C-257C-257C-26sdata-3DxLi1w2e1udcuc3Kwz7xGgmhZSeuqdOo0ajkq6jRqOZo-253D-26reserved-3D0&d=DwMFAg&c=mRWFL96tuqj9V0Jjj4h40ddo0XsmttALwKjAEOCyUjY&r=w05DwAF0P7ofwV4XZt1zDuW3aSHj2h4ep8o8gzwYbJo&m=jqvkIJB1NySchJN98MdlTIL-w2sMGBQoJzDm7Fg9kbkMGvxMmv1KljUsoQsT9IKp&s=OZ3kdU3_4Thv7D8cD6FHtr09KipZKy25zR9APveMxmc&e="><span style="color:#0563C1">ITHAKA</span></a> </span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:black">301 E. Liberty St, Suite 250, Ann Arbor, MI 48104<br>
Email: <a href="mailto:Spencer.Thomas@ithaka.org"><span style="color:#0563C1">Spencer.Thomas@ithaka.org</span></a></span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:black">Voicemail: +1-734-887-7004</span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:black"><a href="https://urldefense.proofpoint.com/v2/url?u=https-3A__nam11.safelinks.protection.outlook.com_-3Furl-3Dhttps-253A-252F-252Furldefense.proofpoint.com-252Fv2-252Furl-253Fu-253Dhttps-2D3A-5F-5Fwww.ithaka.org-5F-2526d-253DDwMF-2Dg-2526c-253DmRWFL96tuqj9V0Jjj4h40ddo0XsmttALwKjAEOCyUjY-2526r-253Dw05DwAF0P7ofwV4XZt1zDuW3aSHj2h4ep8o8gzwYbJo-2526m-253DFUytUOszF6u1h8HnN-2DDI-5FKv6s8vLU5eCFdhIJBFjVOa-2DJxl0iyomlKsYqEnOpRmE-2526s-253DyA6pvruWzOEpvdkwsi93VD2ROpHBPWlwbuAGWtFbcaY-2526e-253D-26data-3D05-257C01-257CM.Koren-2540elsevier.com-257Cf67c24b06f5a4c37019408dae3b5822a-257C9274ee3f94254109a27f9fb15c10675d-257C0-257C0-257C638072666408236143-257CUnknown-257CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0-253D-257C2000-257C-257C-257C-26sdata-3DxLi1w2e1udcuc3Kwz7xGgmhZSeuqdOo0ajkq6jRqOZo-253D-26reserved-3D0&d=DwMFAg&c=mRWFL96tuqj9V0Jjj4h40ddo0XsmttALwKjAEOCyUjY&r=w05DwAF0P7ofwV4XZt1zDuW3aSHj2h4ep8o8gzwYbJo&m=jqvkIJB1NySchJN98MdlTIL-w2sMGBQoJzDm7Fg9kbkMGvxMmv1KljUsoQsT9IKp&s=OZ3kdU3_4Thv7D8cD6FHtr09KipZKy25zR9APveMxmc&e="><span style="color:#0563C1">ithaka.org</span></a> </span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:windowtext"><img border="0" width="211" height="51" style="width:2.1979in;height:.5312in" id="Picture_x0020_2" src="cid:image002.png@01D91E87.4FE8B7D0" alt="ITHAKA logo"></span><o:p></o:p></p>
</div>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:windowtext"> </span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:windowtext"> </span><o:p></o:p></p>
<div>
<p class="MsoNormal" style="margin-left:1.0in"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:windowtext">On 12/21/22, 1:32 PM, "users" <<a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a>> wrote:</span><o:p></o:p></p>
</div>
<p class="MsoNormal" style="margin-left:1.0in"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:windowtext"> </span><o:p></o:p></p>
<div id="demo">
<table class="MsoNormalTable" border="0" cellspacing="0" cellpadding="0" width="100%" style="width:100.0%;margin-left:1.0in;background:yellow;border-collapse:collapse">
<tbody>
<tr>
<td width="100%" style="width:100.0%;border:double windowtext 1.0pt;padding:.75pt .75pt .75pt .75pt">
<p class="MsoNormal"><strong><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:red">Caution</span></strong><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:red">: This message did not originate from within ITHAKA's email
 system. Please use caution when opening attachments and following links within this message.
</span><o:p></o:p></p>
</td>
</tr>
</tbody>
</table>
<p class="MsoNormal" style="margin-left:1.0in"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:windowtext"><img border="0" width="50" height="50" style="width:.5208in;height:.5208in" id="_x0000_i1031" src="cid:image001.gif@01D91E87.4FE8B7D0"></span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><span style="font-size:12.0pt;color:#98AFF3">Hi,</span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><span style="font-size:12.0pt;color:#98AFF3"> </span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><span style="font-size:12.0pt;color:#98AFF3">I’m writing from the City University of New York. We’re attempting to enable SAML2 SSO with
</span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><span style="font-size:12.0pt;color:#98AFF3">a vendor who would configure a service provider instance for each of our 26 campuses—except
</span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><span style="font-size:12.0pt;color:#98AFF3">for one problem that I have never encountered in my years of configuring Shibboleth.
</span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><span style="font-size:12.0pt;color:#98AFF3"> </span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><span style="font-size:12.0pt;color:#98AFF3">Their system will not accept the same IDP entity ID for two or more SPs. We have one SP instance
</span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><span style="font-size:12.0pt;color:#98AFF3">configured in their system  (and in ours as a relying party) with our IDP metadata (we’re running IDP 4.0.1).
</span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><span style="font-size:12.0pt;color:#98AFF3">This integration works as expected. When they attempt to configure a new SP instance, their system
</span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><span style="font-size:12.0pt;color:#98AFF3">generates the error message, “Duplicate IDP Entity ID. Another IDP profile has the same Entity ID.”</span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><span style="font-size:12.0pt;color:#98AFF3"> </span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><span style="font-size:12.0pt;color:#98AFF3">Am I correct that this constraint on IDP and SP entityIDs is nonstandard?</span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><span style="font-size:12.0pt;color:#98AFF3"> </span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><span style="font-size:12.0pt;color:#98AFF3">In case I have made an unwarranted assumption about their system, the SAML2 specification or both, is there
</span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><span style="font-size:12.0pt;color:#98AFF3">a way to generate separate metadata for the same IDP with different entityIDs? One of their customers
</span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><span style="font-size:12.0pt;color:#98AFF3">(another university) provided the vendor with IDP metadata of the form entityID=constantURL?variableID=theID.
</span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><span style="font-size:12.0pt;color:#98AFF3">The ACS etc endpoints in their metadata also contained the additional argument. I do not know if this customer stood
</span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><span style="font-size:12.0pt;color:#98AFF3">up separate IDPs.</span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><span style="font-size:12.0pt;color:#98AFF3"> </span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><span style="font-size:12.0pt;color:#98AFF3">I feel as though I ought to apologize for this.</span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><span style="font-size:12.0pt;color:#98AFF3"> </span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><span style="font-size:12.0pt;color:#98AFF3"> </span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><span style="font-size:12.0pt;color:#98AFF3">Sincerely,</span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><span style="font-size:12.0pt;color:#98AFF3"> </span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><span style="font-size:12.0pt;color:#98AFF3">Florian</span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><span style="font-size:12.0pt;color:#98AFF3"> </span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><span style="font-size:12.0pt;color:#98AFF3"> </span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><span style="font-size:12.0pt;color:#98AFF3"> </span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:black"><img border="0" width="176" height="96" style="width:1.8333in;height:1.0in" id="Picture_x0020_3" src="cid:image003.png@01D91E87.4FE8B7D0"></span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><span style="font-size:9.0pt;color:#00B0F0">Florian Lengyel, PhD</span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><span style="font-size:9.0pt;color:#00B0F0">Identity and Access Management</span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><span style="font-size:9.0pt;color:#00B0F0">CUNY CIS 395 Hudson Street, New York, NY 10014</span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><span style="font-size:9.0pt;color:#00B0F0">Voicemail: (646) 664-2370 Cell: (917) 621-7845</span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><span style="font-size:9.0pt;color:#00B0F0">Email:
<a href="mailto:florian.lengyel@cuny.edu">florian.lengyel@cuny.edu</a></span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:1.0in"><span style="font-size:12.0pt"> </span><o:p></o:p></p>
</div>
</div>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:windowtext"><o:p> </o:p></span></p>
<div class="MsoNormal" align="center" style="text-align:center"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:windowtext">
<hr size="2" width="100%" align="center">
</span></div>
<p><span style="font-size:10.0pt;font-family:"Arial",sans-serif">Elsevier B.V. Registered Office: Radarweg 29, 1043 NX Amsterdam, The Netherlands, Registration No. 33158992, Registered in The Netherlands.</span>
<o:p></o:p></p>
</div>
</body>
</html>