How to set up simplesaml for the IDP and Shibboleth for the SP Was: Re: Broke - delete user session

trey trey at westcampus.net
Mon Oct 21 15:27:54 EDT 2013


Hey Scott,


Thank you for you quick reply.  That's great to hear that Shibboleth
IDP can use MySql. I'd looked into it long ago and had written that
off, thinking it only worked with LDAP+ SQL with a great deal of
hacking.
However, the complexity of setting up the Shibboleth IDP had really
kept me from progressing on it sooner. It's possible I can set it all
up I think (I've tried at least twice) but the value return in
exchange, was just not high enough for what we were neeeding right at the
moment with the time available to work on it. I want to
eventually use Shibboleth for both SP and IDP now knowing that
Shibboleth IDP can indeed use MySql.  That's really good information.  
Thank you for confirming that!
First, I want to use simplesaml as the IDP as a learning exercise and  
because it's just... ...well, "simpler" .

Also, I was also recommended by someone who runs a company managing
Shibboleth installations to not use Shibboleth IDP when it sounded
like I could just use simplesaml for my purpose and that I should
continue with simplesaml since I'm a novice still. So fore now,
simplesaml it is!

> Yes, do each one separately and that's it.
>
> -- Scott
>

This sounds interesting. Indeed! please elaborate... :D

Oh btw, I did get the SP to talk to TestShib. I can log into TestShib  
after being redirected from the SP, and it comes back with attributes  
that I can use. I now need to put the SP metadata inside the  
simplesaml IDP and the IDP metadata inside the Shibboleth SP; I just  
don't know where to put it (which hosted filed/format?).
I'm wodering if it's, that the metadata is in the wrong place. I'm
going from memory here because I'm not at the computers that have the
Shibboleth SP and simplesaml IDP (links are cached in browser), but I
think I did something like:

At the IDP, generated the IDP metadata the Shibboleth SP side would need at:
http://192.168.23.110/simplesaml/saml2/idp/metadata.php
(got a lot of xml data)

At the SP, generated the  SP medata that the  simplesaml IDP would need at:
http://192.168.23.111/Shibboleth.sso/Metadata
(got a download prompt, contains xml metadata for the Shibboleth SP  
including entityID= line)

Then on the simplesaml IDP side, I used:
http://192.168.23.110/simplesaml/admin/metadata-converter.php
to get the shibboleth SP metadata into a format that simplesaml  
needed. Looks like php code.

I hunted around the internet and determined that I needed to put that
converted text into a file on the IDP, but am not sure which one. Also
I'm not sure where to put the IDP metadata on my Shibboleth SP.

I think I'm almost there but just need a little help on the last part
to get over the hump. Can you help?


Thanks!



Quoting "Cantor, Scott E. [via Shibboleth]"
<ml-node+s1660669n7590551h42 at n2.nabble.com>:

>
>
> On 10/14/13 2:43 AM, "trey" <trey at westcampus.net> wrote:
>
>> I have been trying for over a week to do what you've accomplished  but
>> can't
>> seem to get the metdata correct (I guess that is the issue). I've looked
>> on
>> the internet a lot and have found plenty of simplesaml SP with Shibboleth
>> IDP documentation.
>
> There is nothing substantial you should have to do with a Shibboleth SP
> here at all. It just works, SSP is perfectly compliant in most respects.
>
>> However, Shibboleth IDP is so complex for my needs as
>> well as it uses LDAP and I prefer to use the mysql connector in simplesaml
>> for looking up  and authenticating users.
>
> Shibboleth can use MySQL just fine. It does *not* require LDAP.
>
>> Can you, or anyone else,  please let me know how you were able to set up
>> simplesaml for the IDP and Shibboleth for the SP?
>
> Yes, do each one separately and that's it.
>
> -- Scott
>
>
> --
> To unsubscribe from this list send an email to       
> users-unsubscribe at shibboleth.net
>
>
>
>
> _______________________________________________
> If you reply to this email, your message will be added to the       
> discussion below:
> http://shibboleth.1660669.n2.nabble.com/Broke-delete-user-session-tp6203911p7590551.html
>
> To unsubscribe from Broke - delete user session, visit       
> http://shibboleth.1660669.n2.nabble.com/template/NamlServlet.jtp?macro=unsubscribe_by_code&node=6203911&code=dHJleUB3ZXN0Y2FtcHVzLm5ldHw2MjAzOTExfC0xMDU2MDY4NjU1










--
View this message in context: http://shibboleth.1660669.n2.nabble.com/Broke-delete-user-session-tp6203911p7590741.html
Sent from the Shibboleth - Users mailing list archive at Nabble.com.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20131021/990bfc28/attachment-0001.html 


More information about the users mailing list