Shibboleth IdP Issuer
Cantor, Scott
cantor.2 at osu.edu
Wed Mar 13 12:08:06 EDT 2013
On 3/13/13 11:27 AM, "Rawlinson, Philip (rawlinpa)"
<RAWLINPA at UCMAIL.UC.EDU> wrote:
>
>When we removed SSL handling on BigIP as a test, the user gets a prompt
>for a client certificate in their browser. If you present a certificate,
>there is a proper SAML1 trust between our IdP and the SAML1 SP and the
>attributes are successfully communicated to EZProxy. However, this is not
>possible as we obviously do not want actual users to have to present a
>certificate to authenticate.
There are two ports involved, and you're trying to combine them. You can't
do that. 443 is for browsers and has no need of client certs, and 8443 is
for SOAP and can't be terminated at the F5 if you want it to work.
-- Scott
More information about the users
mailing list