Shibboleth.sso not replying on SP in 2.3.1

Ken Demarest ken.demarest at gmail.com
Fri Oct 5 12:45:49 EDT 2012


On Ubuntu using shibboleth 2.3.1 on apache2.2 when I visit:

https://mydomain.com/Shibboleth.sso/Metadata

it appears that mod_shib is not intercepting the url, and I'm passed
through to my (Rails Passenger) application, which of course responds that
it can't find the file.

However, I am certain that mod_shib is installed and working, because when
I visit my shibboleth-protected directory (/auth/shibboleth/) I get
correctly redirected to the idp.

My understanding (maybe wrong) is that mod_shib captures all traffic
heading for /Shibboleth.sso/ and handles it.

I think (again maybe wrongly) that the directory name Shibboleth.sso is
defined for shib 2.3.1 in the shibboleth2.xml file, with this line:

<Sessions lifetime="28800" timeout="3600" checkAddress="false"
            handlerURL="/Shibboleth.sso" handlerSSL="true"
            exportLocation="http://localhost/Shibboleth.sso/GetAssertion"
exportACL="127.0.0.1"
            idpHistory="false" idpHistoryDays="7">

But it isn't working.

I've done one other installation, with shibboleth 2.5, and it eventually
worked fine (on OSX) with a MUCH simpler shibboleth2.xml file.

I suspect that somehow Apache is masking the Shibboleth.sso directory from
mod_shib, so it never gets handed over to shibd. (am I right?)

To further confirm the problem, when I log in to the idp, it replies with:

No peer endpoint available to which to send SAML response

I imagine this is because it can't find /Shibboleth.sso/ and the
subdirectories shibd simulates, which the idp would normally interact with.


*Things I've tried:*

1. Lots of googling to see if others have had this problem. Not much out
there.

2. Commenting out some apache conf lines that did Rewrites.  Didn't help.

3. Added a <Location> command to make sure /Shibboleth.sso/ was accessible.
Didn't help.

Next I'm trying:

1. I'll strip down to a super bare-bones apache conf and see if something
I've eliminated was the problem.

2. Doing a manual build of shib 2.5 on that machine and using my
configuration that works on OSX (with appropriate adjustments of course)

But I don't have much hope.

Here is my shibboleth2.xml file:

<SPConfig xmlns="urn:mace:shibboleth:2.0:native:sp:config"
    xmlns:conf="urn:mace:shibboleth:2.0:native:sp:config"
    xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"
    xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"
    xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata"
    logger="syslog.logger" clockSkew="180">


    <OutOfProcess logger="shibd.logger">

    </OutOfProcess>

    <!-- The InProcess section conrains settings affecting web server
modules/filters. -->
    <InProcess logger="native.logger">
        <ISAPI normalizeRequest="true" safeHeaderNames="true">

            <Site id="1" name="appsoma.com"/>

        </ISAPI>
    </InProcess>

    <!-- Only one listener can be defined, to connect in-process modules to
shibd. -->
    <UnixListener address="shibd.sock"/>
    <!-- <TCPListener address="127.0.0.1" port="12345" acl="127.0.0.1"/> -->

    <!-- This set of components stores sessions and other persistent data
in daemon memory. -->
    <StorageService type="Memory" id="mem" cleanupInterval="900"/>
    <SessionCache type="StorageService" StorageService="mem"
cacheTimeout="3600" inprocTimeout="900" cleanupInterval="900"/>
    <ReplayCache StorageService="mem"/>
    <ArtifactMap artifactTTL="180"/>

    <RequestMapper type="Native">
        <RequestMap applicationId="default">
            <Host name="appsoma.com">
                <Path name="secure" authType="shibboleth"
requireSession="true"/>
            </Host>
        </RequestMap>
    </RequestMapper>

    <ApplicationDefaults id="default" policyId="default"
        entityID="https://appsoma.com/shibboleth"
        REMOTE_USER="eppn persistent-id targeted-id"
        signing="false" encryption="false">

        <Sessions lifetime="28800" timeout="3600" checkAddress="false"
            handlerURL="/Shibboleth.sso" handlerSSL="true"
            exportLocation="http://localhost/Shibboleth.sso/GetAssertion"
exportACL="127.0.0.1"
            idpHistory="false" idpHistoryDays="7">

            <SessionInitiator type="Chaining" Location="/Login"
isDefault="true" id="Intranet"
                    relayState="cookie" entityID="
https://idp.its.utexas.edu/idp/shibboleth">
                <SessionInitiator type="SAML2" acsIndex="1"
template="bindingTemplate.html"/>
                <SessionInitiator type="Shib1" acsIndex="5"/>
            </SessionInitiator>

            <SessionInitiator type="Chaining" Location="/WAYF" id="WAYF"
relayState="cookie">
                <SessionInitiator type="SAML2" acsIndex="1"
template="bindingTemplate.html"/>
                <SessionInitiator type="Shib1" acsIndex="5"/>
                <SessionInitiator type="WAYF" acsIndex="5" URL="
https://wayf.example.org/WAYF"/>
            </SessionInitiator>

            <SessionInitiator type="Chaining" Location="/DS" id="DS"
relayState="cookie">
                <SessionInitiator type="SAML2" acsIndex="1"
template="bindingTemplate.html"/>
                <SessionInitiator type="Shib1" acsIndex="5"/>
                <SessionInitiator type="SAMLDS" URL="
https://ds.example.org/DS/WAYF"/>
            </SessionInitiator>

            <md:AssertionConsumerService Location="/SAML2/POST" index="1"
                Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"/>
            <md:AssertionConsumerService Location="/SAML2/POST-SimpleSign"
index="2"

Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign"/>
            <md:AssertionConsumerService Location="/SAML2/Artifact"
index="3"

Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact"/>
            <md:AssertionConsumerService Location="/SAML2/ECP" index="4"
                Binding="urn:oasis:names:tc:SAML:2.0:bindings:PAOS"/>
            <md:AssertionConsumerService Location="/SAML/POST" index="5"

Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post"/>
            <md:AssertionConsumerService Location="/SAML/Artifact" index="6"
                Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01"/>

            <!-- LogoutInitiators enable SP-initiated local or
global/single logout of sessions. -->
            <LogoutInitiator type="Chaining" Location="/Logout"
relayState="cookie">
                <LogoutInitiator type="SAML2"
template="bindingTemplate.html"/>
                <LogoutInitiator type="Local"/>
            </LogoutInitiator>

            <!-- md:SingleLogoutService locations handle single logout
(SLO) protocol messages. -->
            <md:SingleLogoutService Location="/SLO/SOAP"
                Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP"/>
            <md:SingleLogoutService Location="/SLO/Redirect"
conf:template="bindingTemplate.html"

Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect"/>
            <md:SingleLogoutService Location="/SLO/POST"
conf:template="bindingTemplate.html"
                Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"/>
            <md:SingleLogoutService Location="/SLO/Artifact"
conf:template="bindingTemplate.html"

Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact"/>

            <md:ManageNameIDService Location="/NIM/SOAP"
                Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP"/>
            <md:ManageNameIDService Location="/NIM/Redirect"
conf:template="bindingTemplate.html"

Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect"/>
            <md:ManageNameIDService Location="/NIM/POST"
conf:template="bindingTemplate.html"
                Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"/>
            <md:ManageNameIDService Location="/NIM/Artifact"
conf:template="bindingTemplate.html"

Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact"/>

            <md:ArtifactResolutionService Location="/Artifact/SOAP"
index="1"
                Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP"/>


            <Handler type="MetadataGenerator" Location="/Metadata"
signing="false"/>

            <!-- Status reporting service. -->
            <Handler type="Status" Location="/Status" acl="127.0.0.1"/>

            <!-- Session diagnostic service. -->
            <Handler type="Session" Location="/Session"
showAttributeValues="false"/>

        </Sessions>

        <Errors supportContact="ken.demarest at gmail.com"
            logoLocation="/shibboleth-sp/logo.jpg"
            styleSheet="/shibboleth-sp/main.css"/>

        <!-- Chains together all your metadata sources. -->
        <MetadataProvider type="Chaining">
            <!-- Example of remotely supplied batch of signed metadata. -->

            <MetadataProvider type="XML"
backingFilePath="/etc/shibboleth/UTfed-metadata.xml" uri="
https://idm.utsystem.edu/downloads/UTfed-metadata.xml"
 reloadInterval="7200">
<!--               <MetadataFilter type="RequireValidUntil"
maxValidityInterval="2419200"/> -->
<!--               <MetadataFilter type="Signature"
certificate="fedsigner.pem"/> -->
            </MetadataProvider>

        </MetadataProvider>

        <!-- Chain the two built-in trust engines together. -->
        <TrustEngine type="Chaining">
            <TrustEngine type="ExplicitKey"/>
            <TrustEngine type="PKIX"/>
        </TrustEngine>

        <!-- Map to extract attributes from SAML assertions. -->
        <AttributeExtractor type="XML" validate="true"
path="attribute-map.xml"/>

        <!-- Use a SAML query if no attributes are supplied during SSO. -->
        <AttributeResolver type="Query" subjectMatch="true"/>

        <!-- Default filtering policy for recognized attributes, lets other
data pass. -->
        <AttributeFilter type="XML" validate="true"
path="attribute-policy.xml"/>

        <!-- Simple file-based resolver for using a single keypair. -->
        <CredentialResolver type="File" key="sp-key.pem"
certificate="sp-cert.pem"/>

        <!-- Example of a second application (using a second vhost) that
has a different entityID. -->
        <!-- <ApplicationOverride id="admin" entityID="
https://admin.example.org/shibboleth"/> -->

    </ApplicationDefaults>


    <SecurityPolicies>

        <Policy id="default" validate="false">
            <PolicyRule type="MessageFlow" checkReplay="true" expires="60"/>
            <PolicyRule type="Conditions">
                <PolicyRule type="Audience"/>
                <!-- Enable Delegation rule to permit delegated access. -->
                <!-- <PolicyRule type="Delegation"/> -->
            </PolicyRule>
            <PolicyRule type="ClientCertAuth" errorFatal="true"/>
            <PolicyRule type="XMLSigning" errorFatal="true"/>
            <PolicyRule type="SimpleSigning" errorFatal="true"/>
        </Policy>
    </SecurityPolicies>

</SPConfig>

And here is the relevant part of the apache configuration:

<IfModule mod_ssl.c>
<VirtualHost _default_:443>

ErrorDocument 503 /503.html
RewriteEngine on
 RewriteCond %{DOCUMENT_ROOT}/../tmp/stop.txt -f
RewriteCond %{DOCUMENT_ROOT}/${REQUEST_FILENAME} !-f
 RewriteRule ^(.*)$ /$1 [R=503,L]

ServerName www.appsoma.com
 DocumentRoot /webapps/hsc/current/public
<Directory /webapps/hsc/current/public>
 Allow from all
Options -MultiViews
 </Directory>

<Location /auth/shibboleth/callback>
 # this Location directive is what redirects apache over to the IdP.
AuthType shibboleth
 ShibRequestSetting requireSession 1
require valid-user
 </Location>

<Location /Shibboleth.sso>
 Satisfy Any
Allow from all
 AuthType None
Require all granted
 </Location>

ErrorLog ${APACHE_LOG_DIR}/error.log

LogLevel warn

 CustomLog ${APACHE_LOG_DIR}/access.log combined

 SSLEngine on

SSLCertificateFile    /etc/apache2/ssl/appsoma.com.crt
 SSLCertificateKeyFile /etc/apache2/ssl/appsoma.com.key

 <FilesMatch "\.(cgi|shtml|phtml|php)$">
SSLOptions +StdEnvVars
 </FilesMatch>
<Directory /usr/lib/cgi-bin>
 SSLOptions +StdEnvVars
</Directory>

BrowserMatch "MSIE [2-6]" \
nokeepalive ssl-unclean-shutdown \
 downgrade-1.0 force-response-1.0
# MSIE 7 and newer should be able to use keepalive
 BrowserMatch "MSIE [17-9]" ssl-unclean-shutdown

</VirtualHost>
</IfModule>

Any and all help is much appreciated!!

Ken Demarest






-- 
____________________________________________________________
______________________
*Ken Demarest *
Founder and President
*JEESTY ENDEAVOR  [ j. ]*
ken.demarest at gmail.com
415.342.9731
Austin, Texas ▪ United States
__________________________________________________________________________________
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20121005/85504599/attachment-0001.html 


More information about the users mailing list