Do I configure multiple Location containers if all vhosts share the same location
csross
cross at hccs.com
Tue Jun 5 17:39:30 BST 2012
Hi,
Thank you very for your help.
My questions are below.
Christine
________________________________
From: Cantor, Scott E. [via Shibboleth]
[mailto:ml-node+s1660669n7579905h96 at n2.nabble.com]
Sent: Tuesday, June 05, 2012 12:09 PM
To: Christine Ross
Subject: Re: Do I configure multiple Location containers if all vhosts
share the same location
On 6/5/12 11:59 AM, "csross" <[hidden email]> wrote:
>
>
>My shibboleth2.xml has a generic ApplicationDefault entityID
>(sp.example.org) and I use ApplicationOverride to specify the entityID,
>applicationID, MetadataProvider, Sessions and SSO entityID for each
vhost
>that is protected.
>>>If you do that, it's much more work. You should have specific reasons
for
>>>doing it, not just because you think it should be that way. So far, I
>>>haven't heard one, and I can tell you that juggling an entityID per
>>>customer is almost always the wrong answer. Not always, but usually.
These are ssl clients so I need a separate IP and vhost for each unique
IP. Every vhost/entityID (I know they aren't the same thing) will have
a different MetadataProvider, SSO entityID and possibly sessions. That
is why I am using ApplicationOverrides. If I get a new client I thought
I would just add another ApplicationOverride section and a vhost in
Apache. We have a wildcard for non-shib clients but the docs say I need
UseCanonicalName On and I don't believe that works with wildcard vhosts.
What is the alternative, using a separate Apache server for each shib
client?
>1) If I do not specify any applicationID in the apache22.config, does
>that
>automatically assign 'default' and then reassign the applicationID set
in
>the ApplicationOverride for that entityID? Reassign is just the word
I
>chose to describe what I am thinking. If this won't assign the correct
id
>this way, I'm thinking I need to create a separate Include file for
each
>vhost.
>>>Everything maps to default out of the box. If you want to override
>>>something, then you need a setting for applicationId to do that. The
>>>setting can be in Apache space or in the RequestMap and the strong
advice
>>>is to do it in Apache because that can't be circumvented.
You said not to use RequestMap because it is Apache. If each
vhost/entityID has the same protected location (/), then the only way I
can see doing that is either in ApplicationDefaults or separate Include
files for each. Is there any other way?
>2) I want each entityID to use the items that are defined in
>ApplicationOverride, and any defaults not defined there. Will this
>accomplish this please?
Mostly. The documentation is the canonical source for how inheritance
works.
>3) Can I redefine anything in the ApplicationOverride that is allowed
the
>default section?
Yes. This is covered in the documentation.
-- Scott
--
To unsubscribe from this list send an email to [hidden email]
________________________________
If you reply to this email, your message will be added to the discussion
below:
http://shibboleth.1660669.n2.nabble.com/Do-I-configure-multiple-Location
-containers-if-all-vhosts-share-the-same-location-tp7579904p7579905.html
To unsubscribe from Do I configure multiple Location containers if all
vhosts share the same location, click here
<http://shibboleth.1660669.n2.nabble.com/template/NamlServlet.jtp?macro=
unsubscribe_by_code&node=7579904&code=Y3Jvc3NAaGNjcy5jb218NzU3OTkwNHwtND
I4NjA4MTk0> .
NAML
<http://shibboleth.1660669.n2.nabble.com/template/NamlServlet.jtp?macro=
macro_viewer&id=instant_html%21nabble%3Aemail.naml&base=nabble.naml.name
spaces.BasicNamespace-nabble.view.web.template.NabbleNamespace-nabble.vi
ew.web.template.NodeNamespace&breadcrumbs=notify_subscribers%21nabble%3A
email.naml-instant_emails%21nabble%3Aemail.naml-send_instant_email%21nab
ble%3Aemail.naml>
--
View this message in context: http://shibboleth.1660669.n2.nabble.com/Do-I-configure-multiple-Location-containers-if-all-vhosts-share-the-same-location-tp7579904p7579906.html
Sent from the Shibboleth - Users mailing list archive at Nabble.com.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20120605/162c0ad3/attachment.html
More information about the users
mailing list