Installation Resources

O'Dowd, Josh Josh.O'Dowd at mso.umt.edu
Fri Feb 10 13:19:22 EST 2017


Everything you need for IDP3.3.0 configuration starts here:
https://wiki.shibboleth.net/confluence/display/IDP30/Configuration


On Feb 10, 2017, at 10:55 AM, Fred Newtz (frnewtz) <frnewtz at cisco.com<mailto:frnewtz at cisco.com>> wrote:

Hello,

I have gone through multiple attempts now to get Shibboleth configured and working properly in our environment.  The installation is easy enough, it is obviously the configuration after the fact where you need a PhD in Shibboleth.  We are using a 3rdparty SP (SAML2.0 compliant), that has been tested and works with Shibboleth in different environments, and want to integrate the Shibboleth IdP (3.3.0) with Active Directory as an LDAP source.  I just need four active directory attributes to be passed, cn, sn, mail, isMember (Group Membership).  Company is an optional value that could also be passed, but that is unimportant.

This seems like a fairly straight forward and standard configuration, but finding information that is still relevant for the latest version of Shibboleth is elusive at best.  Does anyone have any suggestions on links to read over to help me understand the best way to go through the configuration to ensure that everything is working as it should.  The link to the configuration page is nice, but it only lists out all of the configuration files and doesn’t really give an order of operations in the best way to go through the configuration and how to test each component to ensure it is working before moving on to the next component.

I have found a few guides on getting Shibboleth IdP installed and configured and working with various SP’s and LDAP backends.  Including Apache Directory Server, but that is not working 100% either at this point.  I can’t imagine there is not a single resource out there that I can use to get a working IdP installation with a valid LDAP configuration on the back end.


Thanks,

Fred


--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net<mailto:users-unsubscribe at shibboleth.net>



More information about the users mailing list