Report of success with SP and IdP test servers, apache 1.3, nginx and SSL off-loading
Cantor, Scott
cantor.2 at osu.edu
Fri Apr 20 15:14:34 BST 2012
On 4/20/12 5:18 AM, "Gernot Hassenpflug" <ha4h-grnt at asahi-net.or.jp> wrote:
>
>- several shibboleth repository *-devel packages *must* be installed
> (else either the creation of SRPMs, or installation of some of the
> created shibboleth RPM packages will fail).
All you should have to do is install shibboleth-devel or whatever it's
called. Most everything else will be installed by that. This isn't
terribly well documented.
>Changes from example-shibboleth2.xml:
>
>1. Site element additions:
> scheme="https"
> port="443"
That does not pertain to Apache. That should be clear from the
documentation.
>2. Site element name, and RequestMap block Host element name changed.
You don't need to use the RequestMap with Apache in most cases. If there
are no settings in it, it doesn't matter what the rest of the map contains.
>7. CredentialResolver element key and certificate values changed.
That shouldn't be necessary in most cases, it generates a keypair for you
and puts them in the right files.
You also missed a crucial step: fix your error templates. If people see a
Shibboleth logo, your site looks bad, and so do we.
-- Scott
More information about the users
mailing list