Shibboleth IdP Issuer

Cantor, Scott cantor.2 at osu.edu
Wed Mar 13 12:08:06 EDT 2013


On 3/13/13 11:27 AM, "Rawlinson, Philip (rawlinpa)"
<RAWLINPA at UCMAIL.UC.EDU> wrote:
>
>When we removed SSL handling on BigIP as a test, the user gets a prompt
>for a client certificate in their browser. If you present a certificate,
>there is a proper SAML1 trust between our IdP and the SAML1 SP and the
>attributes are successfully communicated to EZProxy. However, this is not
>possible as we obviously do not want actual users to have to present a
>certificate to authenticate.

There are two ports involved, and you're trying to combine them. You can't
do that. 443 is for browsers and has no need of client certs, and 8443 is
for SOAP and can't be terminated at the F5 if you want it to work.

-- Scott




More information about the users mailing list