users Digest, Vol 55, Issue 115

Yasser Afifi yasser at 3dissue.com
Fri Jan 22 12:09:04 EST 2016


Hello Scott,
Thanks for the reply
I am trying to send attributes from idp to sp. I configured the soap back
channel for this (any other suggestions?)
I get an error because the sp can't identity tomcat certificate!
this is the error i get:
2016-01-22 12:41:38 INFO Shibboleth.Listener : listener service starting
2016-01-22 12:42:17 ERROR XMLTooling.SOAPTransport.CURL [1]: supplied
TrustEngine failed to validate SSL/TLS server certificate
2016-01-22 12:42:17 ERROR XMLTooling.SOAPTransport.CURL [1]: Certificate:

2016-01-22 12:42:17 ERROR Shibboleth.AttributeResolver.Query [1]: exception
during SAML query to
https://localhost:8443/idp/profile/SAML2/SOAP/AttributeQuery:
CURLSOAPTransport failed while contacting SOAP endpoint (
https://localhost:8443/idp/profile/SAML2/SOAP/AttributeQuery): SSL
certificate problem: application verification failure
2016-01-22 12:42:17 ERROR Shibboleth.AttributeResolver.Query [1]: unable to
obtain a SAML response from attribute authority
2016-01-22 12:42:17 INFO Shibboleth.SessionCache [1]: new session created:
ID (_04e70c190b8b7c9f5d2097632a420471) IdP (
https://localhost:8443/idp/shibboleth)
Protocol(urn:oasis:names:tc:SAML:2.0:protocol) Address (::1)

Any help would be welcome!
Thanks again,
Kind Regards,
Yasser


On 22 January 2016 at 17:00, <users-request at shibboleth.net> wrote:

> Send users mailing list submissions to
>         users at shibboleth.net
>
> To subscribe or unsubscribe via the World Wide Web, visit
>         http://shibboleth.net/mailman/listinfo/users
> or, via email, send a message with subject or body 'help' to
>         users-request at shibboleth.net
>
> You can reach the person managing the list at
>         users-owner at shibboleth.net
>
> When replying, please edit your Subject line so it is more specific
> than "Re: Contents of users digest..."
>
>
> Today's Topics:
>
>    1. Re: 'Deep linking' in Shibboleth (Cantor, Scott)
>    2. configuring soap back-channel on tomcat (Yasser Afifi)
>    3. Re: configuring soap back-channel on tomcat (Cantor, Scott)
>
>
> ----------------------------------------------------------------------
>
> Message: 1
> Date: Fri, 22 Jan 2016 14:51:28 +0000
> From: "Cantor, Scott" <cantor.2 at osu.edu>
> To: Shib Users <users at shibboleth.net>
> Subject: Re: 'Deep linking' in Shibboleth
> Message-ID: <0733144C-9110-49BA-86EF-971CA2A851EA at osu.edu>
> Content-Type: text/plain; charset="utf-8"
>
> On 1/22/16, 9:48 AM, "users on behalf of Zico" <
> users-bounces at shibboleth.net on behalf of mailzico at gmail.com> wrote:
>
>
>
> >Thanks Eric for your great description!
> >So.. what I can understand .. there is actually nothing to do from IDP
> side to facilitate deep linking.
>
> Nothing that isn't already required by SAML. That doesn't mean there
> aren't broken IdPs that don't support the standard fully, so I wouldn't say
> there's nothing the IdP has to do.
>
> -- Scott
>
>
> ------------------------------
>
> Message: 2
> Date: Fri, 22 Jan 2016 16:29:37 +0000
> From: Yasser Afifi <yasser at 3dissue.com>
> To: users at shibboleth.net
> Subject: configuring soap back-channel on tomcat
> Message-ID:
>         <CAC=Xfo+39Gu+K0dK_yHv+3igS=8bXfFJ-b28Cyi8n2=
> jm3kzAg at mail.gmail.com>
> Content-Type: text/plain; charset="utf-8"
>
> Hello again,
>
> I am trying to configure tomcat for SOAP endpoints as per instruction in
> this wiki:
> https://wiki.shibboleth.net/confluence/display/SHIB2/IdPApacheTomcatPrepare
>
> but tomcat won't start listening on port 8443 once i enter this
> configuration. I am also guessing there is a mismatch between the tomcat
> certificate and the certificate on the idp-metadata.xml but i am not sure
> how to match them because i get this error:
> SSL certificate problem: application verification failure
> My SP can't verify tomcat certificate for some reason. Tomcat certificate
> is different from the one in the idp-metadata. But in the same time i can't
> configure tomcat to use the certificate in the idp as per instruction in
> the link above
>
> Any suggestions?
>
> Kindest Regards,
> Yasser
> -------------- next part --------------
> An HTML attachment was scrubbed...
> URL: <
> http://shibboleth.net/pipermail/users/attachments/20160122/708b0076/attachment-0001.html
> >
>
> ------------------------------
>
> Message: 3
> Date: Fri, 22 Jan 2016 16:36:16 +0000
> From: "Cantor, Scott" <cantor.2 at osu.edu>
> To: Shib Users <users at shibboleth.net>
> Subject: Re: configuring soap back-channel on tomcat
> Message-ID: <9A148425-AFCE-41DE-B0F3-23BF8A466BC6 at osu.edu>
> Content-Type: text/plain; charset="utf-8"
>
> On 1/22/16, 11:29 AM, "users on behalf of Yasser Afifi" <
> users-bounces at shibboleth.net on behalf of yasser at 3dissue.com> wrote:
>
>
>
> >I am trying to configure tomcat for SOAP endpoints as per instruction in
> this wiki:
> >
> >
> https://wiki.shibboleth.net/confluence/display/SHIB2/IdPApacheTomcatPrepare
>
> 1. Are you running V3 or V2? If V2, stop it. If V3, that's not the right
> page.
>
> 2. Why are you using the back channel? Why do you think you need to? Did
> you review the documentation explaining why you would or wouldn't need it?
>
> -- Scott
>
>
> ------------------------------
>
> Subject: Digest Footer
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
> ------------------------------
>
> End of users Digest, Vol 55, Issue 115
> **************************************
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160122/f9e2f973/attachment.html>


More information about the users mailing list