Shibboleth 2.4.3 SAML2 and WAYF

Cantor, Scott cantor.2 at
Fri Jan 13 20:08:27 GMT 2012

On 1/13/12 3:00 PM, "Law, Bob" <Robert.Law at> wrote:

>That is probably due to me simply copying the daemon into
>shibboleth/shibd and not replacing all of the files in
>shibboleth/etc/shibboleth except for shibboleth2.xml.

Ok, well, no. Don't do that. You need to make install, nothing else is
going to work.

>So I have a half
>way working implementation.  I will copy all of the files over and see
>what works out.

Don't do that either. You will never get it correct doing anything but
make install (using gmake).

Your config in an old install tree will not be overwritten in any way by
doing that. But that assumes a full install tree from a previous make
install. Anything else is not something I can predict, but in general, the
config install step is simply "if same file exists, don't overwrite".

>  I may decide to delete the old shibboleth entirely.  Am
>I correct in assuming that the embedded discovery service can replace my
>WAYF and support both clients that are either SAML2 or SAML1?  I know
>that would make my life much simpler.


-- Scott

