Problem with SOAP call to 2.4.4 IdP / port 8443 / F5 load balancer
Cantor, Scott
cantor.2 at osu.edu
Tue Nov 10 10:57:16 EST 2015
On 11/10/15, 12:53 AM, "users on behalf of Benji Wakely" <users-bounces at shibboleth.net on behalf of B.Wakely at latrobe.edu.au> wrote:
> Previously working httpd frontend/tomcat backend (Shib IdP 2.4.4) fails to work for SOAP
>back-channel binding after putting it behind a load balancer.
I would imagine you've broken mutual TLS. You'll either have to stop proxying HTTP or convince the SP(s) to sign their messages.
>
>
>I’m aware of how httpd magically Doesn’t Mangle client certificates using AJP (+ExportCertData option),
>I’ve set up the F5 so it should in theory be passing traffic straight through / not acting as an intermediate as such [2] but Something is still getting mangled.
If you're not doing end to end TLS, there's no way for the SP's certificate to be associated with the request. If you are, then I don't know what you mean by mangled. Whose certificate is the IdP seeing?
-- Scott
More information about the users
mailing list