SSL offloading breaks ECP

Cantor, Scott cantor.2 at osu.edu
Fri Jan 25 15:07:15 EST 2013


On 1/25/13 2:56 PM, "Ryan Suarez" <ryan.suarez at sheridancollege.ca> wrote:

>I've got a working shib IdP behind F5 load balancers.  Web SSO and ECP
>(for Office 365) works fine.
>
>But if I terminate SSL at the load balancers like so:
>https://lists.internet2.edu/sympa/arc/shibboleth-users/2008-12/msg00351.ht
>ml
>
>Web SSO works but it breaks ECP.  I don't really understand how ECP is
>affected, still troubleshooting.  I don't see any debug logs on the IdP
>regarding ECP.  It would be greatly appreciated if someone can offer
>tips or point me in the right direction.

I can't think of anything it would affect, so without knowing what the
error is, I can't really say. It shouldn't be debug logs at issue, the
question is what the error is.

Of course, ECP is (normally) basic auth, so if your offloading doesn't
forward that information, clearly it isn't going to work, but that should
be self-evident.

-- Scott




More information about the users mailing list