Shibboleth + Jasig CAS

Gianluigi Ruggeri gianluigi83 at gmail.com
Wed Nov 27 04:11:40 EST 2013


Hi all,
thank you for your reply..
Probably I not have understood very well the question about Shibbolteth
 metadata.

1) I have Installed my Shibbholet idp.
2) I deployed the war file on Tomcat.

Now I have to generate/change metadata file?
when I try to test my shibboleth idp I have this error:

2013-11-27 03:38:13 WARN Shibboleth.SessionInitiator.SAML2 [1021]:
unable to locate metadata for provider
(https://vincenteservices.resiltech.net/idp/shibboleth)


and if I try to get this url (
https://vincenteservices.resiltech.net/idp/shibboleth) I see this xml file:


This XML file does not appear to have any style information associated with
it. The document tree is shown below.
<EntityDescriptor xmlns="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="
http://www.w3.org/2000/09/xmldsig#" xmlns:shibmd="
urn:mace:shibboleth:metadata:1.0" xmlns:xsi="
http://www.w3.org/2001/XMLSchema-instance" entityID="
https://vincenteservices.resiltech.net/idp/shibboleth">
<IDPSSODescriptor protocolSupportEnumeration="urn:mace:shibboleth:1.0
urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:2.0:protocol">
<Extensions>
<shibmd:Scope regexp="false">resiltech.net</shibmd:Scope>
</Extensions>
<KeyDescriptor>
<ds:KeyInfo>
<ds:X509Data>
<ds:X509Certificate>
MIIDZjCCAk6gAwIBAgIVAIaHSXOjlb5TdqKQbVaYGJms/7ihMA0GCSqGSIb3DQEB
BQUAMCkxJzAlBgNVBAMTHnZpbmNlbnRlc2VydmljZXMucmVzaWx0ZWNoLm5ldDAe
Fw0xMzExMjUxNDMyMjJaFw0xNjExMjUxNDMyMjJaMCkxJzAlBgNVBAMTHnZpbmNl
bnRlc2VydmljZXMucmVzaWx0ZWNoLm5ldDCCASIwDQYJKoZIhvcNAQEBBQADggEP
ADCCAQoCggEBAIvSctsTN0kvd0DWugpArGaevRBOOdDMnmMzIhDcOhU3jeaGfZ+W
wZFyjfz0RmkBMBxzDUUTUPPyY2+5pmQTbSrky7CrLrXqjgvAx62g+gpH6xOJD1qG
KmYtk/chYjBgMUUQq26OgETylpSlwbCuq61kkxPO3M73CbbNiyAbB6/ZNrQoRBfo
QN/gdo/afPXMGOZCf3o4D/7u12D8bn8Tn0iz+camKde8OmTHeKnZrd/xoBah3J+5
6DK1jpRp3u4H0IozD/GaMaSfJS3gMLMo25MGRQ8BRNa/64sCCl43xbwUKbc21Q6P
nLeMpqYOXrjUPINoGnAUHSj2bDnJRFuflccCAwEAAaOBhDCBgTBgBgNVHREEWTBX
gh52aW5jZW50ZXNlcnZpY2VzLnJlc2lsdGVjaC5uZXSGNWh0dHBzOi8vdmluY2Vu
dGVzZXJ2aWNlcy5yZXNpbHRlY2gubmV0L2lkcC9zaGliYm9sZXRoMB0GA1UdDgQW
BBTz4ijGG+6mD7qG5/IAFwINgDyPuzANBgkqhkiG9w0BAQUFAAOCAQEABcz9Vhm9
znI+Qh6srqqrS9TQeixLfAQJ8oUyW0I1A8+VeHotUyQal6tafVjvXAj79jb7TOKs
p2vOKKPv8o5YZCwjgbp9R7h1SfifZwn7TrxyFIUCYJ77ExFojjpu5/mYz6SL9XNe
PWTOCsV1GjMohPBSb62WskBIYiz2D/3D90wRu/D6Dq3KBJYOkqK7dOC3mkepHC9p
aWlIXrQhRx/MTMjhi2k9CzBTATUuvcAHAUrsbmpWSMuAdCuqRrDTjvYFfPPS49Cf
33IhFtV6ke4lw03GP391JUVr4W6Qyxcv7PBTssZW4ttqep5+RIo9pOmmgufbxW38
hYeuWfe9xqyx3A==
</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</KeyDescriptor>
<ArtifactResolutionService Binding="
urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="
https://vincenteservices.resiltech.net:8443/idp/profile/SAML1/SOAP/ArtifactResolution
" index="1"/>
<ArtifactResolutionService Binding="
urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="
https://vincenteservices.resiltech.net:8443/idp/profile/SAML2/SOAP/ArtifactResolution
" index="2"/>
<SingleLogoutService Binding="
urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="
https://vincenteservices.resiltech.net/idp/profile/SAML2/Redirect/SLO"/>
<SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST
" Location="
https://vincenteservices.resiltech.net/idp/profile/SAML2/POST/SLO"/>
<SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP"
Location="
https://vincenteservices.resiltech.net:8443/idp/profile/SAML2/SOAP/SLO"/>
<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
<NameIDFormat>
urn:oasis:names:tc:SAML:2.0:nameid-format:transient
</NameIDFormat>
<SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest"
 Location="https://vincenteservices.resiltech.net/idp/profile/Shibboleth/SSO
"/>
<SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST
" Location="
https://vincenteservices.resiltech.net/idp/profile/SAML2/POST/SSO"/>
<SingleSignOnService Binding="
urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="
https://vincenteservices.resiltech.net/idp/profile/SAML2/POST-SimpleSign/SSO
"/>
<SingleSignOnService Binding="
urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="
https://vincenteservices.resiltech.net/idp/profile/SAML2/Redirect/SSO"/>
</IDPSSODescriptor>
<AttributeAuthorityDescriptor
protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol
urn:oasis:names:tc:SAML:2.0:protocol">
<Extensions>
<shibmd:Scope regexp="false">resiltech.net</shibmd:Scope>
</Extensions>
<KeyDescriptor>
<ds:KeyInfo>
<ds:X509Data>
<ds:X509Certificate>
MIIDZjCCAk6gAwIBAgIVAIaHSXOjlb5TdqKQbVaYGJms/7ihMA0GCSqGSIb3DQEB
BQUAMCkxJzAlBgNVBAMTHnZpbmNlbnRlc2VydmljZXMucmVzaWx0ZWNoLm5ldDAe
Fw0xMzExMjUxNDMyMjJaFw0xNjExMjUxNDMyMjJaMCkxJzAlBgNVBAMTHnZpbmNl
bnRlc2VydmljZXMucmVzaWx0ZWNoLm5ldDCCASIwDQYJKoZIhvcNAQEBBQADggEP
ADCCAQoCggEBAIvSctsTN0kvd0DWugpArGaevRBOOdDMnmMzIhDcOhU3jeaGfZ+W
wZFyjfz0RmkBMBxzDUUTUPPyY2+5pmQTbSrky7CrLrXqjgvAx62g+gpH6xOJD1qG
KmYtk/chYjBgMUUQq26OgETylpSlwbCuq61kkxPO3M73CbbNiyAbB6/ZNrQoRBfo
QN/gdo/afPXMGOZCf3o4D/7u12D8bn8Tn0iz+camKde8OmTHeKnZrd/xoBah3J+5
6DK1jpRp3u4H0IozD/GaMaSfJS3gMLMo25MGRQ8BRNa/64sCCl43xbwUKbc21Q6P
nLeMpqYOXrjUPINoGnAUHSj2bDnJRFuflccCAwEAAaOBhDCBgTBgBgNVHREEWTBX
gh52aW5jZW50ZXNlcnZpY2VzLnJlc2lsdGVjaC5uZXSGNWh0dHBzOi8vdmluY2Vu
dGVzZXJ2aWNlcy5yZXNpbHRlY2gubmV0L2lkcC9zaGliYm9sZXRoMB0GA1UdDgQW
BBTz4ijGG+6mD7qG5/IAFwINgDyPuzANBgkqhkiG9w0BAQUFAAOCAQEABcz9Vhm9
znI+Qh6srqqrS9TQeixLfAQJ8oUyW0I1A8+VeHotUyQal6tafVjvXAj79jb7TOKs
p2vOKKPv8o5YZCwjgbp9R7h1SfifZwn7TrxyFIUCYJ77ExFojjpu5/mYz6SL9XNe
PWTOCsV1GjMohPBSb62WskBIYiz2D/3D90wRu/D6Dq3KBJYOkqK7dOC3mkepHC9p
aWlIXrQhRx/MTMjhi2k9CzBTATUuvcAHAUrsbmpWSMuAdCuqRrDTjvYFfPPS49Cf
33IhFtV6ke4lw03GP391JUVr4W6Qyxcv7PBTssZW4ttqep5+RIo9pOmmgufbxW38
hYeuWfe9xqyx3A==
</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</KeyDescriptor>
<AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding
" Location="
https://vincenteservices.resiltech.net:8443/idp/profile/SAML1/SOAP/AttributeQuery
"/>
<AttributeService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP"
Location="
https://vincenteservices.resiltech.net:8443/idp/profile/SAML2/SOAP/AttributeQuery
"/>
<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
<NameIDFormat>
urn:oasis:names:tc:SAML:2.0:nameid-format:transient
</NameIDFormat>
</AttributeAuthorityDescriptor>
</EntityDescriptor>



Are correct these steps? Why I obtain an error about the metadata?
An other question: I use a tomcat with my certificate (SSL)...is correct
regenerate an other certificate as requested during the shibbolteh
instalaltion? Is possibile that this is a problem?


2013/11/25 Kevin P. Foote <kpfoote at iup.edu>

>
> On Mon, 25 Nov 2013, Gianluigi Ruggeri wrote:
>
> > 5. To test I restarted the Tomcat servlet container and I verified that
> CAS
> > authentication is used. I used the TestShib Service Provider but I have
> > this error:
> >
> > opensaml::saml2md::MetadataException
> >
> > TestShib encountered some sort of error while processing your request
> > issued at Mon Nov 25 06:08:04 2013.
>
> Have you registered your metadata with the testshib service?
>
>
> <https://testshib.org/register.html>
>
> ------
> thanks
>   kevin.foote
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20131127/a2947f4b/attachment.html 


More information about the users mailing list