Problems with back-channel connection
Adam Portier
aportier at haverford.edu
Tue Oct 8 10:34:04 EDT 2013
Thank you for your response. The logout I am trying to do is via the
"Shibboleth.sso/Logout" in the default SP config. It is configure to do
both a Local and SAML2 logout action. When it tries to do the SAML2 logout
action, that's when I see the error page and the connection attempt to the
IdP back-channel. My point is that it looks like my back-channel
communication isn't working at all (initial connection or anything
afterward).
I am using Apache to proxy the HTTPS via an AJP connector on port 8009,
using a guide I found online. However, I am letting Tomcat host 8443
directly. Does that change anything about your suggestion?
I will also work on adding attributes into the SAML assertion. I didn't
really need any for the proof of concept I was working on, but I will put
some in there.
On Tue, Oct 8, 2013 at 10:09 AM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> On 10/8/13 10:05 AM, "Cantor, Scott" <cantor.2 at osu.edu> wrote:
> >
> >If you're using Apache in front of the IdP, not doing that might be one
> >fix.
>
> But of course the underlying fix is, don't use the back channel and fix
> your attribute release issue at the IdP.
>
> -- Scott
>
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
--
Adam Portier
Linux Administrator
IITS Core Technologies
Haverford College
W: 610-896-2974
C: 240-409-9759
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20131008/ec3d99ff/attachment-0001.html
More information about the users
mailing list