X.509 Authentication using Tomcat

nduan at dtechspace.com nduan at dtechspace.com
Thu Feb 20 14:56:11 EST 2014


Thanks Scott.  I would hope that this package can work out of the box 
to support X509 on Tomcat, but it didn't work with the latest Shibboleth 
IdP 2.4.0.  This is what I did:

1. Followed the instructions on the wiki page to download the 
x509-login-handler source from forge.switch.ch.
2. Built the x509-login-handler package using JDK 1.6 (had to specify 
the servlet-api dependency in pom.xml file)
3. Modified the configuration files according to the instructions on 
wiki page (disabled the LDAP connector part so just to test the 
authentication part) and generated the deployment idp.
4. Configure the tomcat server to enable 2-way SSL
5. Start the tomcat IdP
6. IdP failed on startup.  Got an error message below.

Apparently there was some configuration steps missing. Not sure if the 
existing config instructions of X509 handler is applicable for idp 
2.4.0.  Any hints would be very helpful.  I didn't run a syntax check on 
the handler.xml file and there was no XML validation error.

Thanks!

ND
------------ Error Message ---------------------
DEBUG 
[edu.internet2.middleware.shibboleth.common.config.BaseReloadableService:136] 
- Initializing shibboleth.HandlerManager service with resources: 
[/opt/shibboleth-idp-x509/conf/handler.xml]
14:40:56.345 - INFO 
[edu.internet2.middleware.shibboleth.common.config.BaseService:158] - 
Loading new configuration for service shibboleth.HandlerManager
14:40:56.360 - ERROR 
[edu.internet2.middleware.shibboleth.common.config.BaseService:188] - 
Configuration was not loaded for shibboleth.HandlerManager service, 
error creating components.  The root cause of this error was: 
org.xml.sax.SAXParseException: cvc-complex-type.2.4.a: Invalid content 
was found starting with element 'LoginHandler'. One of 
'{"urn:mace:shibboleth:2.0:idp:profile-handler":LoginHandler}' is 
expected.

On 2014-02-20 10:46, Cantor, Scott wrote:
> On 2/20/14, 12:43 PM, "nduan at dtechspace.com" <nduan at dtechspace.com> 
> wrote:
> 
>> Apparently the X509 Login Handler
>> (https://wiki.shibboleth.net/confluence/display/SHIB2/X.509+Login+Handler)
>> was written for using Apache Httpd as the front end of the Shibboleth
>> Java IdP.  Could someone provide any insight on how to make X509
>> authentication to work directly with Tomcat without the Httpd?
> I see no evidence any of that is true based on a very short look. The
> servlet pulls from the standard Java attribute populated with a TLS 
> client
> credential. Apache's got nothing to do with it.
> -- Scott
> 
> --
> To unsubscribe from this list send an email to 
> users-unsubscribe at shibboleth.net



More information about the users mailing list