Red Hat Enterprise 6 and libcurl
Brian Reindel
brian at reindel.com
Fri Sep 13 13:21:11 EDT 2013
SELinux is not enabled. I saw that on the Nabble archives and Google
and checked.
When Shibboleth uses curl to connect to grab the metadata from the IdP
it is hitting Apache via SSL. If Apache were misconfigured so that the
cipher suite doesn't match with the cipher that curl is using then
that might be the reason for the error I'm seeing from shibd -t.
(Unknown cipher in list). I'm really trying to confirm if this is an
installation issue or a configuration issue. On RHE6 should I have to
change anything by default to get shibd to use the alternative libcurl
included in /opt/shibboleth/lib64? If I'm seeing the LD_LIBRARY_PATH
as present, and the library exists at that location, then I shouldn't
have to do anything else, correct?
As far as the log files are concerned, do you have any insights into
why I would not see any? For Linux isn't /var/log/shibboleth where
they should be printing out in a default install?
Brian
On Fri, Sep 13, 2013 at 11:23 AM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> On 9/13/13 11:04 AM, "Brian Reindel" <brian at reindel.com> wrote:
>
>>Okay, I see that now, and it is referenced. However, we still seem to
>>be having issues. When I access the service provider I get the
>>following message:
>>
>>"Cannot connect to shibd process, a site adminstrator should be notified."
>
> The box probably has SELinux enabled.
>
>>There are no logs in /var/log/shibboleth, and the only way I can
>>identify any issues is by using the shibd -t command. Regarding the
>>original message, my Apache configuration for the SSLCipherSuite is as
>>follows:
>
> Has nothing to do with Shibboleth or the use of libcurl in Shibboleth.
>
> -- Scott
>
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list