Delegated Auth with

Eric Dalquist eric.dalquist at
Thu Nov 3 20:24:49 GMT 2011

No joy with FireFox & modifying the headers (captured using a SSL 
capable proxy)

GET /secure/printenv HTTP/1.1
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:7.0.1) Gecko/20100101 
Accept: application/vnd.paos+xml
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip, deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
DNT: 1
Connection: keep-alive

HTTP/1.1 302 Found
Date: Thu, 03 Nov 2011 20:13:17 GMT
Server: Apache
path=/; secure
Expires: Wed, 01 Jan 1997 12:00:00 GMT
Cache-Control: private,no-store,no-cache,max-age=0

Content-Length: 747
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/html; charset=iso-8859-1

<title>302 Found</title>
<p>The document has moved <a 

You are more than welcome to poke at if you'd like. I've 
attached the shib config for the server (note my original email was 
about a target server named j2eedev and this is my-dev) just to make 
sure we're all on the same page.

We'll look into enabling the native log. Also we're not above manually 
adding logging to various places in the SP source (since we compile from 
source on Solaris) and recompiling to find out more of what is going on, 
we'd just need some pointers on where to add the logging :)


On 11/03/2011 01:57 PM, Cantor, Scott wrote:
> On 11/3/11 1:58 PM, "Eric Dalquist"<eric.dalquist at>  wrote:
>> The code did work and what I'm seeing on the wire shows unescaped values
>> being sent to Apache.
> Ok. I'll have to look closer, but nothing is coming to mind here. Short of
> debugging it or adding a logging statement to capture it, I don't know
> what to say. Can you try a test using Firefox and Modify Headers? See if
> you can get that SP to recognize it if the browser sends those headers. I
> do that for testing.
>> Not sure if it helps at all but this is all we see in the shibd logs for
>> the request:
> The native log would be the relevant one, but it probably won't show much.
> All I can think of is that the setting is not being honored. For that to
> be true, you'd probably have to be editing the wrong XML file and not
> actually changing the real config, but I'm sure that's easy enough to
> prove wrong.
> -- Scott
> --
> To unsubscribe from this list send an email to users-unsubscribe at
-------------- next part --------------
A non-text attachment was scrubbed...
Name: shibboleth2.xml
Type: text/xml
Size: 16889 bytes
Desc: not available
Url : 
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 7430 bytes
Desc: S/MIME Cryptographic Signature
Url : 

More information about the users mailing list