New Shibboleth daemon on new server - user/wayf page just reloads over and over

Cantor, Scott cantor.2 at osu.edu
Wed Sep 18 21:15:37 EDT 2013


On 9/18/13 6:41 PM, "Johnny Lasker" <jlasker at educause.edu> wrote:

>Today, we tried the config that gets generated with testshib and had good
>results. I've attached the config that lets us authenticate against
>testshib and returns us back to our site. It also has a commented out
>section by the SSO and metadataprovider elements showing what we really
>need to use to offer authentication against our pool of Incommon idps.

Using testshib has no material difference from using a real IdP, but what
you're doing there is bypassing discovery. Since the problem here has to
be with your discovery service, that just avoids the issue.

>I checked the transaction log and I see a difference between the two
>settings:

That's not the log I need. Please turn both up to DEBUG and provide a
trace of both native and shibd log when the looping occurs.

>I'm assuming that the lack of a session id is a big factor, would
>something like that be affected by our config settings? Because, if we can
>change from one source to another (our incommon xml vs. testshib) and have
>one generate session ids and the other not, without changing any server
>settings, it seems like we are just missing something with our config.

No, that's a bug of some kind that causes a transaction log entry when
there shouldn't be one. The issue is with your custom discovery code, I am
fairly certain of that.

As a test, something you could try is to point your discoveryURL at the
InCommon discovery service. That might be a good way of teasing something
out.

-- Scott




More information about the users mailing list