IIS integration question
Caskey, Paul
pcaskey at utsystem.edu
Tue Jul 2 08:56:33 EDT 2013
This is a weird one...
We have an on-prem vendor app (RSA Archer) that installs as an app on an IIS web server.
The app supports header-based SSO integration, so getting that working with shibb was pretty easy.
That was version 5.3 of the vendor app. Install service pack1 - 5.3_SP1 - and it breaks the shibb ISAPI filter. Or, rather, it precedes it, intercepting all "unknown" requests and sending them to it's default home page.
The problem is as easy to reproduce as just installing Archer 5.3SP1 or greater, change nothing, install shibb, configure nothing, and you can't even get to the shibb status page (or anything else thar runs under the Shibboleth.sso handler, including bogus handler URLs), even though the handler installed fine in IIS. Same scenario works fine prior to SP1.
Sadly, the vendor (who did reproduce the issue in their lab) claims this was an intended change and that nothing is broken, therefore they will not be fixing it.
So, my question is: Does anyone know of a way to put the shibb ISAPI filter back in front of that app - give it higher priority, etc in IIS?
We can always proxy this, but just curious if there is a way to fix it directly.
Thanks!
More information about the users
mailing list