New Shibboleth daemon on new server - user/wayf page just reloads over and over
Ben Turner
bturner at educause.edu
Thu Sep 12 11:40:48 EDT 2013
Hello
I've been monitoring the list and going through archives to see if I can diagnose and resolve my issues that I'm having with setting up another web server to run the shibboleth daemon service. After spending several days we've got the 2.3.1 version of the daemon service logging the exact same results on start-up as our working environment however we are now stuck without much of a clue on how to resolve our issue.
working environment with inCommon/Shibboleth login:
https://www.educause.edu/Shibboleth.sso/DS?target=https%3A%2F%2Fwww.educause.edu%2Fshib_login%2Fhome
new environment that isn't working:
https://new.educause.edu/Shibboleth.sso/DS?target=https%3A%2F%2Fnew.educause.edu%2Fshib_login%2Fhome
What we're seeing is the user reaches the user/wayf resource on new.educause.edu and they select an institution then it simply reloads the user/wayf page without any notice, error or warning. I've confirmed that our incommon.xml file is writing correctly and we're not seeing anything in the logs for shibd.txt, native.txt, native_warn.txt or shibd_warn.txt pertaining to any interactions from end users.
So I am running out of ideas and documentation to read. I was wondering if anyone recognized the behavior of just reloading the user/wayf page? We have identified with tcpdumps that our service is communicating out to the institutions but I am unable to do any deep inspections on that traffic as its traversing over SSL.
Is there anymore aggressive logging settings we can use or any tools/tests that anyone would suggest we try to help with identifying the problem? We're running the same code on new.educause.edu that we have operating the service correctly on www.educause.edu. We've also successfully setup this new SP with Internet2 to new.educause.edu should be a recognized SP.
Help please and I'll be forever indebted
Ben Turner
More information about the users
mailing list