Shibboleth + Jasig CAS
Gianluigi Ruggeri
gianluigi83 at gmail.com
Mon Dec 2 09:07:52 EST 2013
Hi all, I have a problem....
I have re configurated another machine in the same way about shibboleth.
I uploaded the metadata file in testShib and I applyed these changes:
"To work with TestShib, you'll need to make a couple minor
modifications to your configuration. We only really need to change
relying-party.xml, located at
/opt/shibboleth-idp/conf/relying-party.xml.
Uncomment the URLMD <MetadataProvider>. Change the metadataURL
tohttp://www.testshib.org/metadata/testshib-providers.xml and the
backingFile to something liketestshib.xml.
Comment out the <MetadataFilter> elements inside the URLMD <MetadataProvider>.
"
when I try to test my shibboleth iDP I see the old error message:
2013-12-02 09:02:34 DEBUG OpenSAML.MessageEncoder.SAML2Redirect
[1048]: message encoded, sending redirect to client
2013-12-02 09:02:45 DEBUG Shibboleth.Listener [1046]: dispatching
message (default/TestShib::run::SAML2SI)
2013-12-02 09:02:45 WARN Shibboleth.SessionInitiator.SAML2 [1046]:
unable to locate metadata for provider
(https://vincenteauth2.resiltech.net:8443/idp/shibboleth)
Why?? The configuration is the same!!
Is possibile to check my metadata file in TestShibb?
2013/12/2 Gianluigi Ruggeri <gianluigi83 at gmail.com>:
> Hi all, I have a problem....
> I have reconfigurate another machine in the same way about shibboleth.
> I uploaded the metadata file in testShib and I applyed these changes:
>
> "To work with TestShib, you'll need to make a couple minor
> modifications to your configuration. We only really need to change
> relying-party.xml, located at
> /opt/shibboleth-idp/conf/relying-party.xml.
>
> Uncomment the URLMD <MetadataProvider>. Change the metadataURL
> tohttp://www.testshib.org/metadata/testshib-providers.xml and the
> backingFile to something liketestshib.xml.
>
> Comment out the <MetadataFilter> elements inside the URLMD <MetadataProvider>.
> "
>
> when I try to test my shibboleth iDP I see the old error message:
>
>
>
>
> 2013/11/27 Kevin P. Foote <kpfoote at iup.edu>:
>>
>> On Wed, 27 Nov 2013, Gianluigi Ruggeri wrote:
>>
>>>
>>> - Is correct to change these blocks in this way (change only the url to my
>>> CAS server)? Is necessary to change also <context-param>
>>> <param-name>serverName</param-name> ? Is necessary to change something
>>> else?
>>
>> Yes that is how you would enable /Authn/RemoteUser
>>
>>> With this configuration when I try to test my Shibbolet Idp (using testshib
>>> service) I have a 500 internal error and I see (in my browser) a redirect
>>> url (in the browser url bar) similar to my host /Authn/RemoteUser
>>
>> Not sure where exactly your error is at the moment..
>>
>> It looks like its perhaps your cas jar files or web.xml or some combo of
>> those two. Double check your class references for the cas client..
>>
>> Sorry cant be of more help at the moment.
>>
>>
>> ------
>> thanks
>> kevin.foote
>> --
>> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list