<div dir="auto"><p dir="ltr">Hello Scott, <br>
Thank you for your reply.</p>
<p dir="ltr">My setup (which integrate Shibboleth with Openstack components such as Horizon-- the web-base service) does not seem to be in need to th the DS, because in Openstack's Horizon login page allows the user to choose which IdP to get authn with, please see the following image.</p><p dir="ltr">do I still need to configure The DS?</p><p dir="ltr"><br><img src="cid:ii_1926db3f9ab7ececa7c1" style="max-width: 100%; height: auto;"><br><br></p></div>
<br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Tue, Oct 8, 2024, 9:47 AM Cantor, Scott <<a href="mailto:cantor.2@osu.edu" target="_blank" rel="noreferrer">cantor.2@osu.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">As Peter said, you're likely confusing discovery with the SP. The SP doesn't do discovery, you need a discovery solution for that part of the problem. The SP simply relies on a standard redirection protocol to invoke one and you tell it to do that.<br>
<br>
Under no circumstances should you be playing games with the SP's old and long dead features to mess around with directing requests. Call a DS, done. That's the only thing you should ever have the SP do to initiate requests if you have > 1 IdP.<br>
<br>
A DS can be a simple web page of links, or a full metadata-backed application.<br>
<br>
-- Scott<br>
<br>
<br>
</blockquote></div>