Adding SAML2 ACS points does not seem to map attributes from SAML2 IDP
Kevin P. Foote
kpfoote at iup.edu
Mon Oct 8 14:03:06 EDT 2012
There are no issues in terminating browser SSL at a loadbalancer (in your case the
F5) for either the Shibboleth-IdP or Shibboleth-SP.
Your back end web servers need to be configured correctly to say who
they are though.. :-)
------
thanks
kevin.foote
On Mon, 8 Oct 2012, Jayashree Ravi wrote:
-> Thanks Scott, We fixed the attribute-map and then we
-> started getting the values. However our operations team has the following
-> to say about SSL:
->
->
->
-> "As a standard for all encrypted web connections SSL
-> certificates are terminated at the F5 load balancer, which make cert management
-> easier for large environments. Please check with Shibboleth developers/support
-> if its possible to patch shibboleth to allow for such a setup to work, this
-> will allow for us to continue to terminate certs on the F5, or is this not an
-> option."
->
->
->
-> Please let us know your thoughts.
->
->
->
-> Thanks again!
->
-> Jayashree
->
->
-> From: cantor.2 at osu.edu
-> To: users at shibboleth.net
-> CC: users at shibboleth.net
-> Subject: Re: Adding SAML2 ACS points does not seem to map attributes from SAML2 IDP
-> Date: Tue, 2 Oct 2012 03:19:11 +0000
->
->
->
->
->
->
-> On Oct 1, 2012, at 3:47 PM, "Jayashree Ravi" <jravi123 at hotmail.com> wrote:
->
->
->
->
->
-> 2. We also have not enabled SSL between our loadbalancer and Apache/Shibboleth and we do have warning messages in shibd_warn.log
->
->
->
->
->
-> You are using SSL with the client, so there is no reason to use settings permitting http client access. The warnings are accurate and should be listened to if you allow only https access to your site.
->
->
->
->
-> -- Scott
->
->
->
-> --
-> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list