UserPassword authn fails with IdP behind reverse proxy

Cantor, Scott cantor.2 at osu.edu
Mon Jul 28 10:10:49 EDT 2014


On 7/28/14, 8:35 AM, "Gregory Cook" <gregorc26 at mail.com> wrote:

>Extracts from idp-process.log are in the attached file - the first
>extract was during a failed authentication (with the reverse proxy) and
>the second was during a successful one (without the reverse proxy).

I'd be looking more at the web logs, but I have no idea what it's doing.

> 
>Our reconfiguration to use the reverse proxy involved only these changes:
>* changed the host:port values in the entityID and SingleSignonService
>Location attributes in idp-metadata.xml on the IdP and SP
>* changed the host:port value in the entityID in shibboleth2.xml on the SP
>* changed the host:port values in the entityID in the Anonymous and
>DefaultRelyingParty provider attributes on the IdP

There should never, ever, be a port in an entityID, nor should it ever be
changed in response to a hostname or proxy configuration. EntityIDs are
names, not locations.

-- Scott



More information about the users mailing list