Report of success with SP and IdP test servers, apache 1.3, nginx and SSL off-loading

Gernot Hassenpflug ha4h-grnt at asahi-net.or.jp
Mon Apr 23 02:46:28 BST 2012


Peter Schober <peter.schober at univie.ac.at> writes:

> * Gernot Hassenpflug <ha4h-grnt at asahi-net.or.jp> [2012-04-20 11:30]:
> > I'd like to lay out below my experience setting up several
> > variations of a shibboleth SP and IdP in-house on CentOS4.8
> > servers. Most of the setup is on the SP side.
> 
> Great to hear that stuff can be made to run on such ancient and mostly
> unsupported software (MySQL 4? httpd 1.3?), though most of what you
> write seems to be very specific for your environment and so should not
> be followed by anyone else.

Many thanks for the feedback. I've read yours, Chad's, and Scott's,
and am making changes, or trying to understand the comments.

> > If it is all bog-standard as far as the developers and expert
> > shibboleth users are concerned, then at least it can stand as an
> > example for users just starting out with configuring shibboleth.
> 
> There's a dedicated "getting started" page for users starting out:
> https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPGettingStarted

Thanks. I had seen that page, but not realized some things.

In particular, I did not realize the importance of customizing the
error templates, but did as documented provide an email address. Now
that I have some understanding, I am customizing the error templates
to say something meaningful.
 
> > IdP Installation/Configuration:
> > -------------------------------
> > 
> > IdP installation was largely trouble-free, using available RPMs on
> > shibboleth SUSE download site
> 
> There are RPM packages available for the IdP?

Oops, my mistake,the IdP package used was the latest source code
package from:
http://www.shibboleth.net/downloads/identity-provider/latest/

In particular, this one:
shibboleth-identityprovider-2.3.6-bin.zip

Regards,
-- 
Gernot Hassenpflug



More information about the users mailing list