Inter-institutional access failure
Peter Schober
peter.schober at univie.ac.at
Wed Dec 5 14:16:26 EST 2012
* It Meme <it.meme01 at gmail.com> [2012-12-05 20:02]:
> We're seeing the occasional "Inter-institutional access failure" messages
> with the EZproxy-Shib integration at our University.
Then look in your ezproxy log files.
> Can anyone offer suggestions on what steps to take to remediate this?
>
> The following link, found via Google, seemed promising:
> https://groups.google.com/forum/m/?fromgroups#!topic/shibboleth-users/1Sd5_6SPBtA
>
> Could you give feedback if we will take approach suggested by
> 'SOLVIS - Nicolas O. Millioud' in the thread?
I doubt that's strictly true what's being said in that thread
("ezProxy only accepts signed responses and encrypted assertions.") as
I can access an ezproxy instance with a Shib IdP using the (current,
as per REL_2 in SVN) defaults of
signResponses="never"
signAssertions="always"
encryptAssertions="conditional"
encryptNameIds="never"
I'd also check your EZproxy version (e.g. for some time EZproxy was
incomptabile with the new defaults when the Shib IdP changed them a
while ago) and consider upgrading EZproxy, as this problem has long
been fixed.
Either way, if you identify the source of the problem (ezproxy log
files) you can certainly adapt your Shib IdP configuration.
-peter
More information about the users
mailing list