ECP extension needed for active clients
Nate Klingenstein
ndk at internet2.edu
Sat Sep 15 19:46:25 EDT 2012
Mauro,
You'll need to enable some form of authentication that ECP can use.
Typically, that will be basic auth, but you just need something that
can set REMOTE_USER.
Please refer to the following documentation and let us know if you
have any problems:
https://wiki.shibboleth.net/confluence/display/SHIB2/IdPEnableECP
Take care,
Nate.
On Sep 15, 2012, at 23:19 , Mauro Minella wrote:
> Hi,
>
> I federated my ShibIdp 2.3.5 with Office365.
> Right now the passive logon does work, using the users’ upn.
>
> However I need the ECP extension at work in order to connect active
> clients (like Outlook).
> I read that ECP extension is included since 2.3.3 and in fact it
> seems it’s in my version yet.
> However, when I try to connect from the active client, I catch the
> following error in my idp log:
> 01:08:44.081 - INFO [Shibboleth-Access:74] - 20120915T230844Z|
> 157.56.252.5|shibidp.eduteamit.com:443|/profile/SAML2/SOAP/ECP|
> 01:08:44.394 - WARN
> [edu
> .internet2
> .middleware.shibboleth.idp.profile.saml2.SAML2ECPProfileHandler:408]
> - REMOTE_USER not set, unable to set principal name
> 01:08:44.394 - ERROR
> [edu
> .internet2
> .middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:429] -
> No return endpoint available for relying party urn:federation:MicrosoftOnline
>
> When I set up the federation, I specified the following values:
> $domainName = "shibdomain.eduteamit.com"
> $passiveLogOnUri = "https://shibidp.eduteamit.com/idp/profile/SAML2/POST/SSO
> "
> $activeLogOnUri = "https://shibidp.eduteamit.com/idp/profile/SAML2/SOAP/ECP
> "
> $issuerUri = "https://shibidp.eduteamit.com/idp/shibboleth"
> $logOffUrl = "https://shibidp.eduteamit.com/idp/logout"
> $tokenSigningCertificate = "MIIDQDCCAiigAwIBA...=
>
>
> Where should I look at now, in order to fix this issue?
>
> Thank you,
>
> Mauro
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20120915/ad00f8f2/attachment.html
More information about the users
mailing list