<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=Windows-1252">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class="elementToProof">
Thanks Scott - those two details have fixed most of the issues.</div>
<div style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class="elementToProof">
<br>
</div>
<div style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class="elementToProof">
In case anyone else has got this running as I'm trying to achieve...has anyone got each Site on its own entityID AND having its own metadata? Azure unfortunately will demand this (and I'll need to leverage Azure app permissions to restrict each app to different
groups of users - as we roll out IdM, we want AAD groups to police access as much as possible).</div>
<div style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class="elementToProof">
<br>
</div>
<div style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class="elementToProof">
(I've seen the note that multiple entityIDs for SSO isn't a good idea, but unless I'm missing something about how to deal with this I don't have a choice).</div>
<div style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class="elementToProof">
<br>
</div>
<div style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class="elementToProof">
TIA</div>
<div class="elementToProof">
<div style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div id="Signature">
<div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<span style="font-size: 10pt;">_________________________________________________</span></div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<span style="font-size: 10pt;"></span></div>
<table style="border-collapse:collapse;border:none;mso-yfti-tbllook:1184;mso-padding-alt:0cm 5.4pt 0cm 5.4pt;mso-border-insideh:none;mso-border-insidev:none">
<tbody>
<tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;height:96.45pt">
<td width="405" valign="top" style="width:303.75pt;padding:0cm 5.4pt 0cm 5.4pt;height:96.45pt">
<p style="margin:0cm 0cm 8pt;line-height:120%;font-size:11pt;font-family:Calibri, sans-serif;margin-bottom:0cm">
<a data-loopstyle="linkonly"><b><span style="font-size:10.0pt;font-family:"Arial",sans-serif;mso-fareast-font-family:"Times New Roman";mso-fareast-language:EN-GB;mso-no-proof:yes">Dave Perry</span></b></a><span style="mso-bookmark:_Hlk16669093"><span style="font-size:12.0pt;font-family:"Times New Roman",serif;mso-fareast-font-family:"Times New Roman";mso-fareast-language:EN-GB"><br>
</span></span><span style="mso-bookmark:_Hlk16669093"><span style="font-size:9.0pt;font-family:"Arial",sans-serif;mso-fareast-font-family:"Times New Roman";mso-fareast-language:EN-GB;mso-no-proof:yes">Application Analyst<span style="mso-spacerun:yes"> </span><b>|<span style="mso-spacerun:yes">
</span></b>Innovation & Technology Services<br>
<br>
</span></span><span style="mso-bookmark:_Hlk16669093"><span style="font-size:9.0pt;font-family:"Arial",sans-serif;mso-fareast-language:EN-GB">York St John University<o:p> </o:p></span></span></p>
<p style="margin:0cm 0cm 8pt;line-height:120%;font-size:11pt;font-family:Calibri, sans-serif;margin-bottom:0cm">
<span style="mso-bookmark:_Hlk16669093"><span style="font-size:9.0pt;font-family:"Arial",sans-serif;mso-fareast-language:EN-GB">Lord Mayor’s Walk, York, YO31 7EX</span></span><span style="mso-bookmark:_Hlk16669093"><span style="font-size:9.0pt;font-family:"Arial",sans-serif;mso-fareast-font-family:"Times New Roman";mso-fareast-language:EN-GB;mso-no-proof:yes"><br>
T: +44(0)1904 876 0000<br>
</span></span><a href="mailto:d.perry1@yorksj.ac.uk" title="mailto:d.perry1@yorksj.ac.uk" data-loopstyle="linkonly" id="OWA3fff16f5-9181-04d6-52e3-ad692ddb7821" class="OWAAutoLink">d.perry1@yorksj.ac.uk</a><span style="mso-bookmark:_Hlk16669093"><span style="font-size:9.0pt;font-family:"Arial",sans-serif;mso-fareast-font-family:"Times New Roman";mso-fareast-language:EN-GB;mso-no-proof:yes"><span style="mso-spacerun:yes">
</span><b>|<span style="mso-spacerun:yes"> </span></b></span></span><a href="http://www.yorksj.ac.uk/" data-loopstyle="linkonly" id="OWA8bd74421-e809-8083-d549-84e9877a5011" class="OWAAutoLink"><span style="mso-bookmark:_Hlk16669093"><span style="font-size:9.0pt;font-family:"Arial",sans-serif;mso-fareast-font-family:"Times New Roman";mso-fareast-language:EN-GB;mso-no-proof:yes;text-underline:none">www.y</span></span><span style="mso-bookmark:_Hlk16669093"><span style="font-size:9.0pt;font-family:"Arial",sans-serif;text-underline:none">orksj</span></span><span style="mso-bookmark:_Hlk16669093"><span style="font-size:9.0pt;font-family:"Arial",sans-serif;mso-fareast-font-family:"Times New Roman";mso-fareast-language:EN-GB;mso-no-proof:yes;text-underline:none">.ac.uk</span></span></a><span style="font-size:9.0pt;font-family:"Arial",sans-serif;mso-fareast-font-family:"Times New Roman";mso-fareast-language:EN-GB;mso-no-proof:yes"><o:p> </o:p></span></p>
</td>
</tr>
<tr style="mso-yfti-irow:1;mso-yfti-lastrow:yes;height:74.7pt">
<td width="405" valign="top" style="width:303.75pt;padding:0cm 5.4pt 0cm 5.4pt;height:74.7pt">
<p style="margin:0cm 0cm 8pt;font-size:11pt;font-family:Calibri, sans-serif;margin-bottom:0cm">
<b><span style="font-size:12.0pt;font-family:"Arial",sans-serif;mso-fareast-font-family:"Times New Roman";mso-fareast-language:EN-GB;mso-no-proof:yes"><o:p><img style="max-width:100%" data-outlook-trace="F:1|T:1" src="cid:1a53c815-6869-478a-b4e2-5f7e4eca3e98"> </o:p></span></b></p>
</td>
</tr>
</tbody>
</table>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<span style="font-size: 10pt;"></span></div>
</div>
</div>
</div>
<div id="appendonsend"></div>
<hr style="display:inline-block;width:98%" tabindex="-1">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Cantor, Scott via users <users@shibboleth.net><br>
<b>Sent:</b> 14 November 2023 17:30<br>
<b>To:</b> users@shibboleth.net <users@shibboleth.net><br>
<b>Cc:</b> Cantor, Scott <cantor.2@osu.edu><br>
<b>Subject:</b> Re: IIS setup</font>
<div> </div>
</div>
<div class="BodyFragment"><font size="2"><span style="font-size:11pt;">
<div class="PlainText">Caution: Please take care when clicking on links or opening attachments in emails that originate from outside of the university. When in doubt, contact the ITS service desk.<br>
<br>
<br>
Back to list (and this is it, see footer).<br>
<br>
> 1, Azure is not auto-detecting if I have a session already. I have to login<br>
> every time I try to access the webapp (hopefully a setting that can resolve<br>
> this?)<br>
<br>
Unless you manually decided to turn on ForceAuthn, that's not an SP issue, it's the IdP deciding to do that.<br>
<br>
> 2, When I've signed in successfully, I get a 404 error when hitting<br>
> siteurl.domain.com/Shibboleth.sso (screenshot attached).<br>
<br>
Generally means SSL offloading or other forms of virtualization (which IIS does not support, again, it's broken), which requires manipulation of the settings in the Site element.<br>
<br>
e.g., The handlerSSL flag set to true, but the requests are over http without TLS so it treats them as standard requests and passes them by.<br>
<br>
> The <ApplicationDefaults> entityID setting in shibboleth2.xml is based on<br>
> the name of the server itself. Is there a better way of setting this up, so you<br>
> use the same IdP for any webapp protected by shibboleth but have<br>
> multiple webapps (each under their own IIS site, with their own Azure<br>
> application to handle the different URLs idea)?<br>
<br>
If you're asking if you can apply a different entityID to the SP itself per vhost, yes, the entityIDSelf setting can be set in the <Host> element to apply a different name automatically. It can also be pattern-driven if the hosts are named well enough for input
into generating decent entityIDs.<br>
<br>
-- Scott<br>
<br>
<br>
--<br>
For Consortium Member technical support, see <a href="https://shibboleth.atlassian.net/wiki/x/ZYEpPw">
https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fx%2FZYEpPw&data=05%7C01%7Cd.perry1%40yorksj.ac.uk%7C7f9f8237f8bb40c9d47d08dbe5376d9b%7C5c8ae38ef85b4309b7ec862815a37aee%7C0%7C0%7C638355798442797706%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=zlLF6x%2BKvsOuQjlA0FXPy280YYTgN3GmmZotrezpocs%3D&reserved=0</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font></div>
</body>
</html>