IdPEnableECP question
dsc123
craig.cook at tulsacc.edu
Mon Dec 2 01:17:28 EST 2013
Thanks for getting back to me, I'm going to have a chance to look at this again tomorrow and had a couple additional questions now.
Looking through the MS O365 intergration white paper there is a short part about enabling ECP in the doc pasted below, it has you define a JNDIRealm in the server.xml
However when enabling the basic authentication for ECP, it references shibuserpassauth in the <login-config> which I have no definition for in server.xml?
Earlier in the documentation it does have this snippet
Ensure the <ph:LoginHandler> element is set as follows:
<ph:LoginHandler xsi:type="ph:UsernamePassword"
jaasConfigurationLocation="file:///C:\Program Files (x86)\Internet2\Shib2Idp/conf/login.config">
<ph:AuthenticationMethod>
urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport
</ph:AuthenticationMethod>
<ph:AuthenticationMethod>
urn:oasis:names:tc:SAML:2.0:ac:classes:unspecified
</ph:AuthenticationMethod>
</ph:LoginHandler>
1. If necessary, modify the <ph:LoginHandler> element to reflect the above settings. More particularly, check that the jaasConfigurationLocation correctly points to the location of the login.config file, which is included in the Shibboleth 2 IdP distribution (in the %IDP_Home%\conf directory).
Does this entry read the login.config and make a realm out of the definition in that file?
jaasConfigurationLocation="file:///C:\Program Files (x86)\Internet2\Shib2Idp/conf/login.config">
Below are the enable ECP instructions, whats the point of the JNDI realm, I don't see anywhere it is being called?
1.1.1.1 Enabling the Shibboleth ECP extension
This section supposes that the ECP extension has been installed as part of the Shibboleth 2 IdP setup (see section § 4.2.6 Installing the IdP ECP Extension on Shibboleth 2 versions prior to 2.3.3 (Optional)).
The first step consists in enabling in the "captive" Tomcat server the HTTP Basic authentication using accounts in our LDAP AD LDS instance. Please note that the Shibboleth ECP extension authentication is currently limited to HTTP Basic authentication.
[Description: Description: Description : Description : procedure_dd]To enable the HTTP Basic authentication, proceed with the following steps:
1. Use Windows Explorer to navigate to %TOMCAT_HOME%\conf, e.g. C:\Program Files (x86)\Internet2\CaptiveTomcat 6.0\conf.
2. Right-click the server.xml file, and then click Edit. The file should open in Notepad.
3. Press Ctrl+F to find "<Realm>".
4. Move to the line BELOW the <Realm> element and insert the following text:
<Realm className="org.apache.catalina.realm.JNDIRealm"
debug="99"
connectionURL="ldap://localhost:389"
authentication="simple"
referrals="follow"
connectionName=" CN=ShibSvc,CN=Users,DC=SHIB,DC=IDMGT,DC=ARCHIMS,DC=FR "
connectionPassword="Password1"
userSearch="(cn={0})"
userBase=" CN=Users,DC=SHIB,DC=IDMGT,DC=ARCHIMS,DC=FR "
userSubtree="false"
allRolesMode = "authOnly" />
Note:
Replace "Shib" and "Password1" by the username and password of your choice.
5. Save and close the server.xml file.
You must then edit the web.xml file in the IdP's source code (located under C:\Program File (x86)\Shib2IdPInstall\src\main\webapp\WEB-INF) to enable the ECP extension and rebuild a WAR file with the install.bat batch file.
[Description: Description: Description : Description : procedure_dd]To enable the ECP extension, proceed with the following steps:
1. Use Windows Explorer to navigate to C:\Program File (x86)\Shib2IdPInstall\src\main\webapp\WEB-INF.
2. Right-click the web.xml file, and then click Edit. The file should open in Notepad.
3. Press Ctrl+F to find "<!-Uncomment to use container managed authentication -->".
4. Move to the line BELOW and insert the following text:
<security-constraint>
<display-name>Shibboleth IdP</display-name>
<web-resource-collection>
<web-resource-name>ECP</web-resource-name>
<url-pattern>/profile/SAML2/SOAP/ECP</url-pattern>
<http-method>GET</http-method>
<http-method>POST</http-method>
</web-resource-collection>
<auth-constraint>
<role-name>*</role-name>
</auth-constraint>
<user-data-constraint>
<transport-guarantee>CONFIDENTIAL</transport-guarantee>
</user-data-constraint>
</security-constraint>
<login-config>
<auth-method>BASIC</auth-method>
<realm-name>ShibUserPassAuth</realm-name>
</lon-config>
5. Save and close the web.xml file.
6. Open a command prompt and navigate to C:\Program File (x86)\Shib2IdPInstall.
7. Run the install.bat batch file to rebuild a WAR file for Shibboleth.
From: Cantor, Scott E. [via Shibboleth] [mailto:ml-node+s1660669n7591746h57 at n2.nabble.com]
Sent: Sunday, November 24, 2013 1:35 PM
To: Craig Cook
Subject: Re: IdPEnableECP question
On 11/22/13, 6:24 PM, "Nate Klingenstein" <[hidden email]</user/SendEmail.jtp?type=node&node=7591746&i=0>> wrote:
>Craig,
>
>It's just saying that you can use the same mechanism that you use to
>protect /idp/Authn/RemoteUser (servlet filter, Apache directives in front
>of AJP, whatever) should also be usable to protect
>/idp/profile/SAML2/SOAP/ECP.
That's probably dubious advice, since I doubt most people using RemoteUser
are actually using basic authentication. I don't know what exactly was in
my mind writing that.
-- Scott
--
To unsubscribe from this list send an email to [hidden email]</user/SendEmail.jtp?type=node&node=7591746&i=1>
________________________________
If you reply to this email, your message will be added to the discussion below:
http://shibboleth.1660669.n2.nabble.com/IdPEnableECP-question-tp7591714p7591746.html
To unsubscribe from IdPEnableECP question, click here<http://shibboleth.1660669.n2.nabble.com/template/NamlServlet.jtp?macro=unsubscribe_by_code&node=7591714&code=Y3JhaWcuY29va0B0dWxzYWNjLmVkdXw3NTkxNzE0fDE3MTM2MzI4NQ==>.
NAML<http://shibboleth.1660669.n2.nabble.com/template/NamlServlet.jtp?macro=macro_viewer&id=instant_html%21nabble%3Aemail.naml&base=nabble.naml.namespaces.BasicNamespace-nabble.view.web.template.NabbleNamespace-nabble.view.web.template.NodeNamespace&breadcrumbs=notify_subscribers%21nabble%3Aemail.naml-instant_emails%21nabble%3Aemail.naml-send_instant_email%21nabble%3Aemail.naml>
image001.png (234 bytes) <http://shibboleth.1660669.n2.nabble.com/attachment/7591994/0/image001.png>
image002.png (234 bytes) <http://shibboleth.1660669.n2.nabble.com/attachment/7591994/1/image002.png>
--
View this message in context: http://shibboleth.1660669.n2.nabble.com/IdPEnableECP-question-tp7591714p7591994.html
Sent from the Shibboleth - Users mailing list archive at Nabble.com.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20131201/52a0c172/attachment-0001.html
More information about the users
mailing list