SAML1.1 attribute release on Shib 3

Morris, Andi amorris at cardiffmet.ac.uk
Wed Feb 15 14:10:35 EST 2017


Strange, we have saml1.1 working with a reverse proxy currently, and it had been working well for years. That's on shib 2.
Short of putting the IdP in the DMZ that's the only way I can see to do it, which could be an option I guess. It's far from ideal however.
Cheers,
Andi

________________________________
From: users <users-bounces at shibboleth.net> on behalf of Cantor, Scott <cantor.2 at osu.edu>
Sent: Wednesday, February 15, 2017 7:04:10 PM
To: Shib Users
Subject: Re: SAML1.1 attribute release on Shib 3

On 2/15/17, 1:58 PM, "users on behalf of Morris, Andi" <users-bounces at shibboleth.net on behalf of amorris at cardiffmet.ac.uk> wrote:

> Alex, thanks also for replying and showing the test sp logs. That really helps to narrow this down. We have a load balancer
> providing reverse proxy, so I guess it must be something that's doing.

You can't reverse proxy the back channel, at least not easily, most older SPs are not going to know to sign their requests and will be expecting to use a client certificate.

This isn't a change, if you have something working today you would have to set it up the same way.

> As far as I know we're not doing any offloading, or similar type
> inspection, but I will definitely look further at that when I'm back in tomorrow.

Proxying is the same as, if not worse and more invasive than, offloading.

-- Scott


--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
________________________________

[Cardiff Metropolitan University - Queens Anniversary Prizes 2015]<http://www.cardiffmet.ac.uk/news/Pages/Cardiff-Met-research-recognised-in-Queens-Anniversary-Prizes-for-Higher-and-Further-Education.aspx>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170215/03d3dadf/attachment.html>


More information about the users mailing list