<div dir="ltr">Thanks for the response. I&#39;m using Lighttpd 1.4.35 which is the latest stable release. <div>FCGI support for SP has a note that it requires patch for Lighttpd bug #322. The description of the bug is &quot;<span style="background-color:rgb(255,255,236);color:rgb(72,72,72);font-family:&#39;Lucida Grande&#39;,verdana,arial,helvetica,sans-serif;font-size:12px">The FastCGI Spec states that authorizers can emit headers of the format Variable-name: value and those variables will be placed into the environment of all subsequent authorized requests as name: value. It would be great if lighttpd supported this</span>&quot; Lighttpd serving only static contents after Authorizer is mentioned in the bug #322 discussion and I&#39;ve seen it reported in other forums - i.e. putting another fcgi responder behind the authorizer or even a php script ends up with Forbidden because the server is correctly configured to not serve scripts as static files.</div>
<div><br></div><div>The patch apparently fixes &quot;<span style="background-color:rgb(255,255,236);color:rgb(72,72,72);font-family:&#39;Lucida Grande&#39;,verdana,arial,helvetica,sans-serif;font-size:12px">All fastcgi mode=authorizer fixes (Variable- env works, proper re-dispatching, and assert failure fix when auth is running in front of cgi)</span>&quot; The problem is the patch only works up to 1.4.24 which is the reason I&#39;m trying to workaround that because I don&#39;t want to be stuck with old version of Lighttpd.</div>
<div><br></div><div>If anyone is successfully using Lighttpd later than 1.4.24 with SP was patching needed? Can you share Lighttpd configuration? I&#39;ve tried to manually patch 1.4.35 but haven&#39;t been successful.</div>
<div><br></div></div><div class="gmail_extra"><br><br><div class="gmail_quote">On Sat, May 24, 2014 at 9:50 PM, Cantor, Scott E. [via Shibboleth] <span dir="ltr">&lt;<a href="/user/SendEmail.jtp?type=node&node=7601115&i=0" target="_top" rel="nofollow" link="external">[hidden email]</a>&gt;</span> wrote:<br>
<blockquote style='border-left:2px solid #CCCCCC;padding:0 1em' class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div class="im HOEnZb">

        On 5/23/14, 9:09 PM, &quot;tadiguy&quot; &lt;<a href="http://user/SendEmail.jtp?type=node&amp;node=7601114&amp;i=0" rel="nofollow" link="external" target="_blank">[hidden email]</a>&gt; wrote:
<div><div class='shrinkable-quote'><br>&gt;
<br>&gt;I have an existing web application that currently interfaces to lighttpd
<br>&gt;via
<br>&gt;fcgi responder and does authentication against a local database. I&#39;m
<br>&gt;trying
<br>&gt;to shibbolize the application and delegate AuthN/AuthZ to Shib. When I put
<br>&gt;my custom fcgi responder behind Shibauthorizer and Shibresponder I hit
<br>&gt;http
<br>&gt;403 forbidden as others have reported (lighttpd only wants to serve static
<br>&gt;pages after the fcgi authorizer - I know there are patches for older
<br>&gt;versions of lighty, but don&#39;t want to patch lighty and can&#39;t use any other
<br>&gt;httpd).
</div></div></div><div class="im HOEnZb">I assume you&#39;re running some kind of ancient version, because AFAIK,
<br>lighttpd was the primary target for the FCGI support in the SP and has
<br>worked fine for plenty of people. Sp I don&#39;t know what limitation you&#39;re
<br>talking ahout, but it&#39;s news to me.
<br><br></div><div class="im HOEnZb">&gt;Given the above constraints, what will be a good way to shibbolize my
<br>&gt;application without making significant changes to my existing fcgi
<br>&gt;responder? My test setup works OK if I serve static pages and I can see
<br>&gt;all
<br>&gt;the shib session variables when I go to
<br>&gt;<a href="https://myhost/Shibboleth.sso/Session" rel="nofollow" link="external" target="_blank">https://myhost/Shibboleth.sso/Session</a>.
<br><br></div><div class="HOEnZb"><div class="h5">Given your constraints stated, there is none, you need to switch servers
<br>or fix lighttpd.
<br><br>-- Scott
<br><br><br></div></div><span class="HOEnZb"><font color="#888888">--
<br>To unsubscribe from this list send an email to <a href="http://user/SendEmail.jtp?type=node&amp;node=7601114&amp;i=1" rel="nofollow" link="external" target="_blank">[hidden email]</a>
<br>

        
        
        
        <br>
        <br>
        <hr noshade size="1" color="#cccccc">
        <div style="color:#444;font:12px tahoma,geneva,helvetica,arial,sans-serif">
                <div style="font-weight:bold">If you reply to this email, your message will be added to the discussion below:</div>
                <a href="http://shibboleth.1660669.n2.nabble.com/Shibbolizing-Existing-Application-tp7601091p7601114.html" target="_blank" rel="nofollow" link="external">http://shibboleth.1660669.n2.nabble.com/Shibbolizing-Existing-Application-tp7601091p7601114.html</a>
        </div>
        <div style="color:#666;font:11px tahoma,geneva,helvetica,arial,sans-serif;margin-top:.4em;line-height:1.5em">
                
                To unsubscribe from Shibbolizing Existing Application, <a href="" target="_blank" rel="nofollow" link="external">click here</a>.<br>

                <a href="http://shibboleth.1660669.n2.nabble.com/template/NamlServlet.jtp?macro=macro_viewer&amp;id=instant_html%21nabble%3Aemail.naml&amp;base=nabble.naml.namespaces.BasicNamespace-nabble.view.web.template.NabbleNamespace-nabble.view.web.template.NodeNamespace&amp;breadcrumbs=notify_subscribers%21nabble%3Aemail.naml-instant_emails%21nabble%3Aemail.naml-send_instant_email%21nabble%3Aemail.naml" rel="nofollow" style="font:9px serif" target="_blank" link="external">NAML</a>
        </div></font></span></blockquote></div><br></div>


        
        
        
<br/><hr align="left" width="300" />
View this message in context: <a href="http://shibboleth.1660669.n2.nabble.com/Shibbolizing-Existing-Application-tp7601091p7601115.html">Re: Shibbolizing Existing Application</a><br/>
Sent from the <a href="http://shibboleth.1660669.n2.nabble.com/Shibboleth-Developers-f1660781.html">Shibboleth - Developers mailing list archive</a> at Nabble.com.<br/>