<div dir="ltr">We have a set of hosts that run Shibboleth, but do so mainly to provide LDAP lookup and CAS functionality for a subset of our users. These hosts do *not* do any SAML authentication, only CAS authentication. <br><br>Every time a CAS login is performed, we get a message in idp-warn.log stating (correctly) that "Metadata resolution failed" -- we do not *HAVE* SAML metadata for these services at this time.<br><br>On <a href="https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/1265631627/CasProtocolConfiguration#Define-Relying-Party-Metadata">https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/1265631627/CasProtocolConfiguration#Define-Relying-Party-Metadata</a> it states that this is the default, expected behavior, but the behavior can be changed so that it looks in the cas registry first (or even better for us, *only*), but I am unable to figure out *how* this is done.<br><br>I naively tried to control this via commenting out parts of our default-relying party (we had to add beans to enable CAS, so I wondered if the order matters), but even with all the Shibboleth and SAML beans commented out, leaving only CAS ones, I was still getting the error.<br><br>Can anyone point me in the right direction?<br clear="all"><div><br></div>-- <br><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><pre cols="72">Jeff Chapin,</pre>Panther eSports Adviser            <br>Systems/Applications Administrator<br>ITS-IS, University of Northern Iowa<br>Phone: 319-273-3162 Email: <a href="mailto:Jeff.Chapin@uni.edu" target="_blank">Jeff.Chapin@uni.edu</a> </div></div></div></div></div>