Issue with Shibboleth idp v2.4.3
Peter Schober
peter.schober at univie.ac.at
Tue Jan 6 08:55:26 EST 2015
* John Hazell <JHazell at esher.ac.uk> [2015-01-06 11:56]:
> We have configured Shibboleth Idp v 2.4.3 on Windows Server 2012 R2
> and everything seems to work using the UK Federation test SP, but
> when we try to log in to some sites, such as the Ja.net community,
> we can log in but then instantly get redirected to our logout page.
That site seems to be running the Shibboleth SP software, so you can
try to establish a session with your own IDP at their SP and see
whether everything worked on the pure SAML/Shibboleth level:
https://community.ja.net/Shibboleth.sso/Login?entityID=https%3A%2F%2Fidp.esher.ac.uk%2Fidp%2Fshibboleth&target=https%3A%2F%2Fcommunity.ja.net%2FShibboleth.sso%2FSession
If that works (as in: shows you an existing Shibboleth session,
potentially with successfully recieved attributes) it's either an
application issue or (more specifically) maybe your IDP is not sending
any required/expected attributes.
Given that the entity in question https://community.ja.net/shibboleth
neither carries an Entity Category nor specifies RequestedAttributes
in its SAML metadata, my bet is on the latter.
Which seems more of a misconfiguration to me: I don't find it very
friendly to have an SP send my IDP a logout request only because they
failed to specify which attributes their SP requires.
-peter
More information about the users
mailing list