IDP Reverse Proxy

Joshua Riffle jriffle at apu.edu
Mon Jul 23 15:52:53 EDT 2012


Hi Scott,
  When the front-facing proxy receives a message on URL at
idp.example.edu(SSL Certificate) it rewrites the URL to communicate
with the back-end
Shibboleth server to shib.example.edu. This breaks the SAML implementation
which (like you said) requires that the URL that receives the message also
matches the SAML EndPoint Location. The original question is whether or not
there is a way of managing this problem via SAML configuration, a hack or
something more elegant. I'm open to options. Do you have any? And yes there
are several conversations about using reverse proxy with IDP Shibboleth but
most of them are several years old. Here's one from 2009:

https://lists.internet2.edu/sympa/arc/shibboleth-users/2009-09/msg00226.html


Joshua Riffle
Software Engineer
*Azusa Pacific University*



On Mon, Jul 23, 2012 at 12:09 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:

> On 7/23/12 3:05 PM, "Joshua Riffle" <jriffle at apu.edu> wrote:
>
> >  Has anyone implemented a front-facing reverse proxy server with a
> >Shibboleth IDP server behind it? If so, what were the reasons for
> >implementing this model and how do you manage your SAML EndPoint not
> >matching the proxy server's URL?
>
> Why would it be a requirement for them *not* to match? The whole point is
> that they have to, so I can tell you that nobody is doing that.
>
> -- Scott
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20120723/c904a0ba/attachment-0001.html 


More information about the users mailing list