<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);" class="elementToProof">
Yea it seems that maybe I'm overthinking this.  I'm already pulling in the IdP-only metadata from InCommon.</div>
<div style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);" class="elementToProof">
I can just tag those entities and then use the relying party config I want based on that.  Since its only IdPs that I'm tagging, the only time my IdP would be interacting with them is during the authn/SAML flow when we are in "SP-mode".  I dont know why I'm
 bothering trying to figure out in code if I'm in SP mode...</div>
<div style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);" class="elementToProof">
<br>
</div>
<div style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);" class="elementToProof">
Thanks for the head up regarding the "registered by InCommon" entity tags.  I was originally thinking about going down this route but now I see that their IdP-only metadata contains entities from other federations.</div>
<div><br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<hr style="display: inline-block; width: 98%;">
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<b>From:</b> users <users-bounces@shibboleth.net> on behalf of Scott Cantor via users <users@shibboleth.net><br>
<b>Sent:</b> Monday, March 9, 2026 2:40 PM<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Cc:</b> Scott Cantor <scott@restingparrotsoftware.com><br>
<b>Subject:</b> [EXTERNAL] Re: authn/SAML outbound entityId </div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-size: 11pt;">Other than timing issues, an SPSSODescriptor role is eventually going to be there, but I doubt I would approach it that way.<br>
<br>
A tag to drive an override would be the expected way to handle this. In principle either set being tagged would work, and it could be simpler to slap a tag on the one metadata source as potentially many.<br>
<br>
Do not make the mistake of assuming "registered by InCommon" is what you want because most IdPs import all of eduGAIN, not just InCommon.<br>
<br>
- Scott<br>
<br>
--<br>
For Consortium Member technical support, see <a data-auth="NotApplicable" class="OWAAutoLink" id="OWAfec9e201-cd8f-6c75-bc97-bc3e250d4afe" href="https://urldefense.proofpoint.com/v2/url?u=https-3A__shibboleth.atlassian.net_wiki_x_ZYEpPw&d=DwICAg&c=CJqEzB1piLOyyvZjb8YUQw&r=YbL7Tj_EqBW9abl6xEy1bs2UfpzD0fSGcxiXJeDGwtg&m=loV9OfshEfl6MZDS2-1IipW3zck_RK_1EkUwTOsUsPkVXLJLrNs9EjvM4LFSbRJO&s=aTgc_fahgH9DTjaD9KDMyKbg1_RCeX6BtJ79YKOian8&e=">
https://urldefense.proofpoint.com/v2/url?u=https-3A__shibboleth.atlassian.net_wiki_x_ZYEpPw&d=DwICAg&c=CJqEzB1piLOyyvZjb8YUQw&r=YbL7Tj_EqBW9abl6xEy1bs2UfpzD0fSGcxiXJeDGwtg&m=loV9OfshEfl6MZDS2-1IipW3zck_RK_1EkUwTOsUsPkVXLJLrNs9EjvM4LFSbRJO&s=aTgc_fahgH9DTjaD9KDMyKbg1_RCeX6BtJ79YKOian8&e=</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</body>
</html>