Questions regarding ECP and ExternalAuthN handler

Carlos Milán Figueredo cmilanf at hispamsx.org
Tue Feb 4 13:35:03 EST 2014


Hi *.*,

I have a working implementation of Shibboleth IdP 2.4.0 and I would like to extend it with ECP, but I have trouble with it. The key here is that the handler currently used is ExternalAuthN, due to integration with other SSO system.

What I would like to know, is:


·         Is it a problem to use ECP while the only active handler are the ExternalAuthN and the PreviousSession one? I'm not getting any log trace from ECP, it seems suspicious.

·         If I go to https://myidp.org/idp/profile/SAML2/SOAP/ECP with the web browser, I keep getting an HTTP authentication request over and over. Should I get a SOAP response when the system is working?

·         I perform the authentication for ECP using JAAS with an LDAP directory. But it's not clear to me how I have to tell Tomcat the place where the login.config file is.

Greets,
Carlos

Carlos Milán Figueredo
HispaMSX System Operator
þ  http://www.hispamsx.org<http://www.hispamsx.org/>
*  telnet://bbs.hispamsx.org<telnet://bbs.hispamsx.org/>


-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20140204/ae457a86/attachment.html 


More information about the users mailing list