SP behind VPN Gateway: handler locations
Peter Schober
peter.schober at univie.ac.at
Fri Aug 26 10:30:48 BST 2011
* Martin Haase <martin.haase at daasi.de> [2011-08-25 17:56]:
> Now I configured this URL in the SP's metadata on the IdP side. The
> problem is, the SP sends the above intranet URL as its ACS. Both do not
> match, so the IdP complains that there's no peer endpoint available etc.
> So how could I achieve that the SP is sending to the IdP the gateway
> address as its ACS, whereas actually receiving the assertion on its
> usual address?
If the ACS URL check at the IdP alone prevents stuff from working you
could apply https://issues.shibboleth.net/jira/browse/SIDP-499 to your
IdP and have the SP sign AuthnRequests.
-peter
More information about the users
mailing list