<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);" class="elementToProof">
I think I see why I was seeing the behavior I reported. The saml authn flow sets up the inbound context, then fetches the relying party config, then sets up the outbound context. I think I was trying to read the outbound context before it was configured...</div>
<div id="appendonsend"></div>
<hr style="display:inline-block;width:98%" tabindex="-1">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Bobby Lawrence via users <users@shibboleth.net><br>
<b>Sent:</b> Monday, March 9, 2026 4:48 PM<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Cc:</b> Bobby Lawrence <robertl@jlab.org><br>
<b>Subject:</b> Re: [EXTERNAL] Re: authn/SAML outbound entityId</font>
<div> </div>
</div>
<style type="text/css" style="display:none">
<!--
p
{margin-top:0;
margin-bottom:0}
-->
</style>
<div dir="ltr">
<div class="x_elementToProof" style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif; font-size:11pt; color:rgb(0,0,0)">
Yea it seems that maybe I'm overthinking this. I'm already pulling in the IdP-only metadata from InCommon.</div>
<div class="x_elementToProof" style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif; font-size:11pt; color:rgb(0,0,0)">
I can just tag those entities and then use the relying party config I want based on that. Since its only IdPs that I'm tagging, the only time my IdP would be interacting with them is during the authn/SAML flow when we are in "SP-mode". I dont know why I'm
bothering trying to figure out in code if I'm in SP mode...</div>
<div class="x_elementToProof" style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif; font-size:11pt; color:rgb(0,0,0)">
<br>
</div>
<div class="x_elementToProof" style="font-family:Aptos,Aptos_EmbeddedFont,Aptos_MSFontService,Calibri,Helvetica,sans-serif; font-size:11pt; color:rgb(0,0,0)">
Thanks for the head up regarding the "registered by InCommon" entity tags. I was originally thinking about going down this route but now I see that their IdP-only metadata contains entities from other federations.</div>
<div><br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<hr style="display:inline-block; width:98%">
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<b>From:</b> users <users-bounces@shibboleth.net> on behalf of Scott Cantor via users <users@shibboleth.net><br>
<b>Sent:</b> Monday, March 9, 2026 2:40 PM<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Cc:</b> Scott Cantor <scott@restingparrotsoftware.com><br>
<b>Subject:</b> [EXTERNAL] Re: authn/SAML outbound entityId </div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div style="font-size:11pt">Other than timing issues, an SPSSODescriptor role is eventually going to be there, but I doubt I would approach it that way.<br>
<br>
A tag to drive an override would be the expected way to handle this. In principle either set being tagged would work, and it could be simpler to slap a tag on the one metadata source as potentially many.<br>
<br>
Do not make the mistake of assuming "registered by InCommon" is what you want because most IdPs import all of eduGAIN, not just InCommon.<br>
<br>
- Scott<br>
<br>
--<br>
For Consortium Member technical support, see <a data-auth="NotApplicable" class="x_OWAAutoLink" id="OWAfec9e201-cd8f-6c75-bc97-bc3e250d4afe" href="https://urldefense.proofpoint.com/v2/url?u=https-3A__shibboleth.atlassian.net_wiki_x_ZYEpPw&d=DwICAg&c=CJqEzB1piLOyyvZjb8YUQw&r=YbL7Tj_EqBW9abl6xEy1bs2UfpzD0fSGcxiXJeDGwtg&m=loV9OfshEfl6MZDS2-1IipW3zck_RK_1EkUwTOsUsPkVXLJLrNs9EjvM4LFSbRJO&s=aTgc_fahgH9DTjaD9KDMyKbg1_RCeX6BtJ79YKOian8&e=">
https://urldefense.proofpoint.com/v2/url?u=https-3A__shibboleth.atlassian.net_wiki_x_ZYEpPw&d=DwICAg&c=CJqEzB1piLOyyvZjb8YUQw&r=YbL7Tj_EqBW9abl6xEy1bs2UfpzD0fSGcxiXJeDGwtg&m=loV9OfshEfl6MZDS2-1IipW3zck_RK_1EkUwTOsUsPkVXLJLrNs9EjvM4LFSbRJO&s=aTgc_fahgH9DTjaD9KDMyKbg1_RCeX6BtJ79YKOian8&e=</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</div>
</body>
</html>