Adding SAML2 ACS points does not seem to map attributes from SAML2 IDP

Kevin P. Foote kpfoote at iup.edu
Mon Oct 8 14:03:06 EDT 2012


There are no issues in terminating browser SSL at a loadbalancer (in your case the 
F5) for either the Shibboleth-IdP or Shibboleth-SP.

Your back end web servers need to be configured correctly to say who
they are though..   :-)

------
thanks
  kevin.foote

On Mon, 8 Oct 2012, Jayashree Ravi wrote:

-> Thanks Scott,  We fixed the attribute-map and then we
-> started getting the values.  However our operations team has the following
-> to say  about SSL:
-> 
->  
-> 
-> "As a standard for all encrypted web connections SSL
-> certificates are terminated at the F5 load balancer, which make cert management
-> easier for large environments. Please check with Shibboleth developers/support
-> if its possible to patch shibboleth to allow for such a setup to work, this
-> will allow for us to continue to terminate certs on the F5, or is this not an
-> option."
-> 
->  
-> 
-> Please let us know your thoughts. 
-> 
->  
-> 
-> Thanks again!
-> 
-> Jayashree
-> 
->  
-> From: cantor.2 at osu.edu
-> To: users at shibboleth.net
-> CC: users at shibboleth.net
-> Subject: Re: Adding SAML2 ACS points does not seem to map attributes from	SAML2 IDP
-> Date: Tue, 2 Oct 2012 03:19:11 +0000
-> 
-> 
-> 
-> 
-> 
-> 
-> On Oct 1, 2012, at 3:47 PM, "Jayashree Ravi" <jravi123 at hotmail.com> wrote:
-> 
-> 
-> 
-> 
-> 
-> 2. We also have not enabled SSL between our  loadbalancer and Apache/Shibboleth  and we do have warning messages in shibd_warn.log 
-> 
-> 
-> 
-> 
-> 
-> You are using SSL with the client, so there is no reason to use settings permitting http client access. The warnings are accurate and should be listened to if you allow only https access to your site. 
-> 
-> 
-> 
-> 
-> -- Scott
-> 
-> 
-> 
-> --
-> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net 		 	   		  


More information about the users mailing list