University of Otago Identity Provider (SAML 2.0 / Shibboleth) — Tuakiri Hosted Login
Otago's SAML 2.0 identity is published as a complete IDPSSODescriptor in the SIGNED Tuakiri NZ Access Federation metadata aggregate, under entityID https://idp.otago.ac.nz/idp/shibboleth with DisplayName "The University of Otago". Confirmed live 2026-08-30: the aggregate returns 200 and 725,866 bytes covering 82 entities, of which two mention Otago. The operator finding is the useful one and it was not previously recorded: Otago owns the entityID, but all six advertised endpoint bindings — SAML2 Redirect/POST/POST-SimpleSign for both SSO and SLO — resolve to hosted-login.tuakiri.ac.nz/hosting/otago.ac.nz/idp/..., which is REANNZ's Tuakiri Hosted Login service (tuakiri-hostedidp-ha.reannz.co.nz). Otago holds the federation identity; REANNZ runs the software. Note also that idp.otago.ac.nz does not exist in DNS — a SAML entityID is a name, not an address, and must not be read as a callable Otago host. This is browser-mediated SSO, not a self-service API: a bare GET to the Redirect/SSO binding returns 500 because it carries no AuthnRequest, which is expected and is not a fault.