From upstream blueprint (https://blueprints.launchpad.net/keystone/+spec/federation-idp-websso): "Currently you have to configure websso globally for keystone. I want to be able to configure it per-IDP so that i can point horizon at those individual websso endpoints rather than have to go through an additional discovery step." See the spec and code reviews in the blueprint link above for more details.
Upstream spec: http://git.openstack.org/cgit/openstack/keystone-specs/tree/specs/liberty/federation-idp-websso.rst
Verified for openstack-keystone-8.0.1-1.el7ost (current puddle).
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://rhn.redhat.com/errata/RHEA-2016-0603.html