Testshib and
Nathan Potter
ndp at opendap.org
Wed Mar 11 09:26:11 EDT 2015
Peter et al.,
I just got back on my Shibboleth project and it was easy enough to get the ECP flow working. I grabbed the ecp.sh example from https://wiki.shibboleth.net/confluence/display/SHIB2/Contributions#Contributions-simplebash and with a few minor edits to make the curl requests of my test SP accept my self-signed certificates (added -k option) it worked like a charm.
It's a great starting point for our work with enabling our data clients to work with Shibboleth.
Thanks for your help!
Nathan
On Feb 27, 2015, at 2:07 AM, Peter Schober wrote:
> * Nathan Potter <ndp at opendap.org> [2015-02-27 01:24]:
>> I'll read about ECP and try to understand what I need to do to my SP
>> to get it to work correctly with the testshib.org instance
>
> 1. Add ECP="true" to the SSO element in your shibboleth2.xml
> 2. There is no step two.
>
> The rest is up to the ECP client, esp. selecting the right endpoint at
> the desired IDP (for a default Shib install that will look something
> like this https://foo.example.org/idp/profile/SAML2/SOAP/ECP ).
> -peter
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
= = =
Nathan Potter ndp at opendap.org
OPeNDAP, Inc. +1.541.231.3317
More information about the users
mailing list