Do I configure multiple Location containers if all vhosts share the same location

csross cross at hccs.com
Tue Jun 5 17:39:30 BST 2012


Hi,

 

Thank you very for your help.

 

My questions are below. 

 

Christine

________________________________

From: Cantor, Scott E. [via Shibboleth]
[mailto:ml-node+s1660669n7579905h96 at n2.nabble.com] 
Sent: Tuesday, June 05, 2012 12:09 PM
To: Christine Ross
Subject: Re: Do I configure multiple Location containers if all vhosts
share the same location

 

On 6/5/12 11:59 AM, "csross" <[hidden email]> wrote: 
> 
> 
>My shibboleth2.xml has a generic ApplicationDefault entityID 
>(sp.example.org) and I use ApplicationOverride to specify the entityID,

>applicationID, MetadataProvider, Sessions and SSO entityID for each
vhost 
>that is protected. 

>>>If you do that, it's much more work. You should have specific reasons
for 
>>>doing it, not just because you think it should be that way. So far, I

>>>haven't heard one, and I can tell you that juggling an entityID per 
>>>customer is almost always the wrong answer. Not always, but usually.

These are ssl clients so I need a separate IP and vhost for each unique
IP.  Every vhost/entityID (I know they aren't the same thing) will have
a different MetadataProvider, SSO entityID and possibly sessions.  That
is why I am using ApplicationOverrides.  If I get a new client I thought
I would just add another ApplicationOverride section and a vhost in
Apache. We have a wildcard for non-shib clients but the docs say I need
UseCanonicalName On and I don't believe that works with wildcard vhosts.

What is the alternative, using a separate Apache server for each shib
client?


>1)  If I do not specify any applicationID in the apache22.config, does 
>that 
>automatically assign 'default' and then reassign the applicationID set
in 
>the ApplicationOverride for that entityID?   Reassign is just the word
I 
>chose to describe what I am thinking.  If this won't assign the correct
id 
>this way, I'm thinking I need to create a separate Include file for
each 
>vhost. 

>>>Everything maps to default out of the box. If you want to override 
>>>something, then you need a setting for applicationId to do that. The 
>>>setting can be in Apache space or in the RequestMap and the strong
advice 
>>>is to do it in Apache because that can't be circumvented. 



You said not to use RequestMap because it is Apache.   If each
vhost/entityID has the same protected location (/), then the only way I
can see doing that is either in ApplicationDefaults or separate Include
files for each.   Is there any other way?


>2)   I want each entityID to use the items that are defined in 
>ApplicationOverride, and any defaults not defined there.  Will this 
>accomplish this please? 

Mostly. The documentation is the canonical source for how inheritance 
works. 

>3)  Can I redefine anything in the ApplicationOverride that is allowed
the 
>default section? 

Yes. This is covered in the documentation. 

-- Scott 

-- 
To unsubscribe from this list send an email to [hidden email] 



________________________________

If you reply to this email, your message will be added to the discussion
below:

http://shibboleth.1660669.n2.nabble.com/Do-I-configure-multiple-Location
-containers-if-all-vhosts-share-the-same-location-tp7579904p7579905.html


To unsubscribe from Do I configure multiple Location containers if all
vhosts share the same location, click here
<http://shibboleth.1660669.n2.nabble.com/template/NamlServlet.jtp?macro=
unsubscribe_by_code&node=7579904&code=Y3Jvc3NAaGNjcy5jb218NzU3OTkwNHwtND
I4NjA4MTk0> .
NAML
<http://shibboleth.1660669.n2.nabble.com/template/NamlServlet.jtp?macro=
macro_viewer&id=instant_html%21nabble%3Aemail.naml&base=nabble.naml.name
spaces.BasicNamespace-nabble.view.web.template.NabbleNamespace-nabble.vi
ew.web.template.NodeNamespace&breadcrumbs=notify_subscribers%21nabble%3A
email.naml-instant_emails%21nabble%3Aemail.naml-send_instant_email%21nab
ble%3Aemail.naml>  



--
View this message in context: http://shibboleth.1660669.n2.nabble.com/Do-I-configure-multiple-Location-containers-if-all-vhosts-share-the-same-location-tp7579904p7579906.html
Sent from the Shibboleth - Users mailing list archive at Nabble.com.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20120605/162c0ad3/attachment.html 


More information about the users mailing list