ECP extension needed for active clients

Nate Klingenstein ndk at internet2.edu
Sat Sep 15 19:46:25 EDT 2012


Mauro,

You'll need to enable some form of authentication that ECP can use.   
Typically, that will be basic auth, but you just need something that  
can set REMOTE_USER.

Please refer to the following documentation and let us know if you  
have any problems:

https://wiki.shibboleth.net/confluence/display/SHIB2/IdPEnableECP

Take care,
Nate.

On Sep 15, 2012, at 23:19 , Mauro Minella wrote:

> Hi,
>
> I federated my ShibIdp 2.3.5 with Office365.
> Right now the passive logon does work, using the users’ upn.
>
> However I need the ECP extension at work in order to connect active  
> clients (like Outlook).
> I read that ECP extension is included since 2.3.3 and in fact it  
> seems it’s in my version yet.
> However, when I try to connect from the active client, I catch the  
> following error in my idp log:
> 01:08:44.081 - INFO [Shibboleth-Access:74] - 20120915T230844Z| 
> 157.56.252.5|shibidp.eduteamit.com:443|/profile/SAML2/SOAP/ECP|
> 01:08:44.394 - WARN  
> [edu 
> .internet2 
> .middleware.shibboleth.idp.profile.saml2.SAML2ECPProfileHandler:408]  
> - REMOTE_USER not set, unable to set principal name
> 01:08:44.394 - ERROR  
> [edu 
> .internet2 
> .middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:429] -  
> No return endpoint available for relying party urn:federation:MicrosoftOnline
>
> When I set up the federation, I specified the following values:
>     $domainName = "shibdomain.eduteamit.com"
>     $passiveLogOnUri = "https://shibidp.eduteamit.com/idp/profile/SAML2/POST/SSO 
> "
>     $activeLogOnUri = "https://shibidp.eduteamit.com/idp/profile/SAML2/SOAP/ECP 
> "
>     $issuerUri = "https://shibidp.eduteamit.com/idp/shibboleth"
>     $logOffUrl = "https://shibidp.eduteamit.com/idp/logout"
>     $tokenSigningCertificate = "MIIDQDCCAiigAwIBA...=
>
>
> Where should I look at now, in order to fix this issue?
>
> Thank you,
>
> Mauro
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20120915/ad00f8f2/attachment.html 


More information about the users mailing list