Problems configuring 2nd SP host to the same IDP

Tony Autin tony.autin at innosoft.ca
Tue Jul 1 14:04:32 EDT 2014


Hi Scott,

These are my latest log entries:

2014-07-01 13:52:53 WARN Shibboleth.Application : insecure cookieProps
>> setting, set to "https" for SSL/TLS-only usage
>
> 2014-07-01 13:52:53 WARN Shibboleth.Application : handlerSSL should be
>> enabled for SSL/TLS-enabled web sites
>
> 2014-07-01 13:52:53 INFO Shibboleth.Application : auto-configuring SSO
>> initiation for protocol (SAML2)
>
> 2014-07-01 13:52:53 INFO Shibboleth.Application : adding SessionInitiator
>> of type (SAML2) to chain (/Login)
>
> 2014-07-01 13:52:53 INFO Shibboleth.Application : auto-configuring
>> ArtifactResolution endpoints for protocol (SAML2)
>
> 2014-07-01 13:52:53 INFO Shibboleth.Application : adding
>> ArtifactResolutionService for Binding
>> (urn:oasis:names:tc:SAML:2.0:bindings:SOAP) at (/Artifact/SOAP)
>
> 2014-07-01 13:52:53 INFO Shibboleth.Application : auto-configuring SSO
>> endpoints for protocol (SAML2)
>
> 2014-07-01 13:52:53 INFO Shibboleth.Application : adding
>> AssertionConsumerService for Binding
>> (urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST) at (/SAML2/POST)
>
> 2014-07-01 13:52:53 INFO Shibboleth.Application : adding
>> AssertionConsumerService for Binding
>> (urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign) at
>> (/SAML2/POST-SimpleSign)
>
> 2014-07-01 13:52:53 INFO Shibboleth.Application : adding
>> AssertionConsumerService for Binding
>> (urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact) at (/SAML2/Artifact)
>
> 2014-07-01 13:52:53 INFO Shibboleth.Application : adding
>> AssertionConsumerService for Binding
>> (urn:oasis:names:tc:SAML:2.0:bindings:PAOS) at (/SAML2/ECP)
>
> 2014-07-01 13:52:53 INFO Shibboleth.Application : auto-configuring SSO
>> initiation for protocol (SAML1)
>
> 2014-07-01 13:52:53 INFO Shibboleth.Application : adding SessionInitiator
>> of type (Shib1) to chain (/Login)
>
> 2014-07-01 13:52:53 INFO Shibboleth.Application : auto-configuring SSO
>> endpoints for protocol (SAML1)
>
> 2014-07-01 13:52:53 INFO Shibboleth.Application : adding
>> AssertionConsumerService for Binding
>> (urn:oasis:names:tc:SAML:1.0:profiles:browser-post) at (/SAML/POST)
>
> 2014-07-01 13:52:53 INFO Shibboleth.Application : adding
>> AssertionConsumerService for Binding
>> (urn:oasis:names:tc:SAML:1.0:profiles:artifact-01) at (/SAML/Artifact)
>
> 2014-07-01 13:52:53 INFO Shibboleth.Application : auto-configuring Logout
>> initiation for protocol (SAML2)
>
> 2014-07-01 13:52:53 INFO Shibboleth.Application : adding LogoutInitiator
>> of type (SAML2) to chain (/Logout)
>
> 2014-07-01 13:52:53 INFO Shibboleth.Application : auto-configuring Logout
>> endpoints for protocol (SAML2)
>
> 2014-07-01 13:52:53 INFO Shibboleth.Application : adding
>> SingleLogoutService for Binding (urn:oasis:names:tc:SAML:2.0:bindings:SOAP)
>> at (/SLO/SOAP)
>
> 2014-07-01 13:52:53 INFO Shibboleth.Application : adding
>> SingleLogoutService for Binding
>> (urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect) at (/SLO/Redirect)
>
> 2014-07-01 13:52:53 INFO Shibboleth.Application : adding
>> SingleLogoutService for Binding
>> (urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST) at (/SLO/POST)
>
> 2014-07-01 13:52:53 INFO Shibboleth.Application : adding
>> SingleLogoutService for Binding
>> (urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact) at (/SLO/Artifact)
>
> 2014-07-01 13:52:53 INFO Shibboleth.Application : auto-configuring Logout
>> initiation for protocol (Local)
>
> 2014-07-01 13:52:53 INFO Shibboleth.Application : adding LogoutInitiator
>> of type (Local) to chain (/Logout)
>
> 2014-07-01 13:52:53 INFO Shibboleth.DiscoveryFeed : feed files will be
>> cached in C:/opt/shibboleth-sp/var/cache/shibboleth/
>
>
Can your expert eyes see something that I'm missing? I see the insecure
cookieProps. I'm not sure if that is my issue.

I have one cert I'm sharing across two sites. One of the sites just uses a
different port. On the site that uses a different port, I've attached an
entirely separate host name. That separate host name is the same one that
i'm using in my shib2.xml config. I don't have a cert attached to that host
name, and don't have shib2.xml configured for it to use SSL.

All of that might be unhelpful, but I figured more information is better
than not enough. If you would like more detail, I'd be happy to provide it.



On Tue, Jul 1, 2014 at 12:48 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:

> > Thanks for the reply. I'm requesting someone with credentials attempt a
> > login, and see what kind of entry I get into the log.
>
> You don't need a login, just access a handler. All of them will throw the
> same error.
>
> -- Scott
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>



-- 
Tony Autin
Director of Implementation and Special Projects
1-888-510-3827 EXT 705
tony.autin at innosoft.ca
www.innosoft.ca
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20140701/a7153e3d/attachment-0001.html 


More information about the users mailing list