Running Shibboleth behind proxy
Cantor, Scott
cantor.2 at osu.edu
Fri Feb 7 19:57:07 EST 2014
On 2/7/14, 7:40 PM, "Nate Klingenstein" <ndk at internet2.edu> wrote:
>Since mutually authenticated TLS connections are generally the basis for
>trust in these exchanges, it's hard to insert a proxy in the middle of
>the conversation. You can sign and encrypt these message instead, which
>will allow the proxy to forward the requests and responses, but it's not
>guaranteed that all IdP implementations will be interoperable with that
>change.
If we're talking about a proxy on the SP network, then in theory that
should work, and won't break TLS (I don't think). The handshake goes
across the proxy transparently, I believe. I forgot about that when I
initially answered. So I don't think signing should be needed.
>What Scott said about the advisability of this is still true regardless,
>and he probably sent you the right Wiki article too.
>
>https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPTransportOpti
>on
Or will be once the wiki is back up in a while.
-- Scott
More information about the users
mailing list