New Shibboleth daemon on new server - user/wayf page just reloads over and over
Johnny Lasker
jlasker at educause.edu
Mon Sep 16 15:05:08 EDT 2013
I'm following up on this post as I work with Ben. We made modifications to
our config to 'modernize' it by swapping out SessionInitiator for SSO,
using just logout, and generally consolidating, but had no luck in
changing our outcome.
We have 2.5.2 installed and are pulling our uncommon.Xml from the cache
folder. We can get the WAYF page to show, but clicking any tile just
redirects to the current page.
https://new.educause.edu/user/wayf?entityID=https%3A%2F%2Fnew.educause.edu%
2Fshibboleth-sp&return=https%3A%2F%2Fnew.educause.edu%2FShibboleth.sso%2FDS
%3FSAMLDS%3D1%26%26target%3Dcookie%253A1379357223_2348
Clicking any tile just redirects back to the current page.
I've attached our current shibboleth2.xml file if anyone has any thoughts
on what's off about it. I also attached our 'modern' version. When we load
try the modern version, we get a 500 error before reaching our WAYF page.
I appreciate any insight or thoughts.
Thank you!
Johnny Lasker Programmer/Analyst
EDUCAUSE <http://www.educause.edu/>
Uncommon Thinking for the Common Good
282 Century Place, Suite 5000, Louisville, CO 80027
direct: 303.544.5677 | main: 303.449.4430 | educause.edu
<http://www.educause.edu/>
On 9/16/13 12:10 PM, "Ben Turner" <bturner at educause.edu> wrote:
>
>
>
>-
>
>Ben Turner, CSM
>Manager, Web Development
>
>EDUCAUSE <http://www.educause.edu/>
>Uncommon Thinking for the Common Good
>282 Century Place, Suite 5000, Louisville, CO 80027
>direct: 303.939.0300 | main: 303.449.4430 | fax: 303.440.0461 |
>educause.edu <http://www.educause.edu/>
>
>
>
>
>
>On 9/13/13 8:42 AM, "Cantor, Scott" <cantor.2 at osu.edu> wrote:
>
>>On 9/12/13 3:58 PM, "Ben Turner" <bturner at educause.edu> wrote:
>>
>>>So I have made the adjustment you suggested with the version of the
>>>shibd
>>>service. We're now running 2.5.2 again and the double ampersand has
>>>been
>>>corrected.
>>
>>Not if the link you sent is the right one.
>>
>>$ curl -ik
>>https://new.educause.edu/Shibboleth.sso/DS?target=https%3A%2F%2Fnew.educa
>>u
>>s
>>e.edu%2Fshib_login%2Fhome
>>
>>
>>Location:
>>https://new.educause.edu/user/wayf?entityID=https%3A%2F%2Fnew.educause.ed
>>u
>>%
>>2Fshibboleth-sp&return=https%3A%2F%2Fnew.educause.edu%2FShibboleth.sso%2F
>>D
>>S
>>%3FSAMLDS%3D1%26%26target%3Dcookie%253A1379082623_e14a
>>
>>Linefeeds will mess with that, but if you look, you'll see this:
>>
>>%3FSAMLDS%3D1%26%26target%3Dcookie%253A1379082623_e14a
>>
>>
>>That decodes as ?SAMLDS=1&&target=cookie:3A1379082623_e14a
>>
>>But I verified not only does it not seem to break the code, but when I
>>manually take it out, it's not making any difference.
>>
>>
>>>Unfortunately we're still seeing the same behavior and we're still not
>>>seeing anything indicating an issue in the various log files.
>>
>>I assume you have logging turned up. I don't know what all the handlers
>>actually log, but they won't log anything normally.
>>
>>>Interestingly enough though, now when I restart the daemon service there
>>>isn't an incommon.xml file created as it was generating it successfully
>>>when we were using 2.3.1. Maybe that has some significance?
>>
>>I seriously doubt that's the case, but your logs would tell you if it
>>were. I suspect you're just not looking in /var/cache.
>>
>>Since manually passing an entityID to /Shibboleth.sso/DS isn't working,
>>my
>>suspicion is you have a broken configuration altogether. You seem to have
>>inappropriate SessionInitiator behavior here. Basically, you have a
>>broken
>>config that's full of old syntax you don't need anyway, so try fixing the
>>problem by modernizing it.
>>
>>Start with defaults, make only specific, relevant changes, do not create
>>SessionInitiators, and switch things to use /Shibboleth.sso/Login instead
>>of the way you're doing it now.
>>
>>Otherwise I don't know what to tell you, but you can try posting your
>>SessionInitiator chain from that endpoint I suppose.
>>
>>-- Scott
>>
>>
>>--
>>To unsubscribe from this list send an email to
>>users-unsubscribe at shibboleth.net
>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: shibboleth2.xml
Type: application/xml
Size: 7402 bytes
Desc: shibboleth2.xml
Url : http://shibboleth.net/pipermail/users/attachments/20130916/eac84690/attachment-0002.rdf
-------------- next part --------------
A non-text attachment was scrubbed...
Name: shibboleth2_modern.xml
Type: application/xml
Size: 10140 bytes
Desc: shibboleth2_modern.xml
Url : http://shibboleth.net/pipermail/users/attachments/20130916/eac84690/attachment-0003.rdf
More information about the users
mailing list