Login Authentication page for shibboleth IDP
Santu Ghosh
mon.snahasish at gmail.com
Wed Nov 22 06:13:15 EST 2017
Hi all
Can anyone help ?
Thanks
On Tue, Nov 21, 2017 at 5:05 PM, Santu Ghosh <mon.snahasish at gmail.com>
wrote:
> Hi David,
>
> I have tried with URL encoding but no luck :(
>
> I observed that when I am trying IDP initiated flow with testshib SP url
> https://sp.testshib.org/shibboleth-sp, its working fine.
> Full IDP initiated url is : https://idp.xxxxx.com/idp/
> profile/SAML2/Unsolicited/SSO?providerId=https://sp.
> testshib.org/shibboleth-sp
> But the same thing is not working when I am using my SP url (although SP
> initiated authentication is working fine for my SP).
>
> Now I am really confused where the problem is.
>
> Attaching my full SP metadata xml, could you please verify it once and
> suggest me where is the actual issue and how to resolve the same.
>
> -------------------------------
> <?xml version="1.0" encoding="UTF-8"?><md:EntityDescriptor
> xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" ID="https___shibboleth-sp-xxxxx.com_shibboleth-sp"
> entityID="https://shibboleth-sp-xxxxx.com/shibboleth-sp"><ds:Signature
> xmlns:ds="http://www.w3.org/2000/09/xmldsig#"><ds:SignedInfo><ds:CanonicalizationMethod
> Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/><ds:SignatureMethod
> Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/><ds:Reference
> URI="#https___shibboleth-sp-xxxxx.com_shibboleth-sp"><ds:Transforms><ds:Transform
> Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/><ds:Transform
> Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/></ds:Transforms><ds:DigestMethod
> Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/><ds:DigestValue>OreU/
> 14CANZdlXlhfpOdBwvjv3E=</ds:DigestValue></ds:Reference></
> ds:SignedInfo><ds:SignatureValue>I0g7LWoPmja4lyu/
> 9HlOeV71rD8djAcSPRVgnEESwMIgcLMR1cacc3HUaztSOE6cwmP+nk/
> vnfhxdp3mSlMnxlwiJVpODSuBZAdSLcMHKy4W0Ah9205X1ev+HqAEz/
> 7VxPke2/dv1rV4bonvs49MA+qCe54F9XtgfoTeVPY+gDqWMerrtUj9G92p2w0F/VIjE50A==
> </ds:SignatureValue><ds:KeyInfo><ds:X509Data><ds:X509Certificate>
> MIIDUjCCAjqgAwIBAgIEUOLIQTANBgkqhkiG9w0BAQUFADBrMQswCQYDVQQG
> EwJGSTEQMA4GA1UE
> CBMHVXVzaW1hYTERMA8GA1UEBxMISGVsc2lua2kxGDAWBgNVBAoTD1JNNSBT
> b2Z0d2FyZSBPeTEM
> MAoGA1UECwwDUiZEMQ8wDQYDVQQDEwZhcG9sbG8wHhOksjQN7xoQZLj9xXefxCFQ69FPcFDeEW
> bHwSoBy5hLPNALaEUoa5zPDwlixwRjFQTc5XXaRpgIjy/2gsL8+
> Y5QRhyXnLqgO67BlLYW/GuHE=</ds:X509Certificate></ds:X509Data>
> </ds:KeyInfo></ds:Signature><md:SPSSODescriptor
> AuthnRequestsSigned="true" WantAssertionsSigned="true"
> protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol"><md:KeyDescriptor
> use="signing"><ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#
> "><ds:X509Data><ds:X509Certificate>MIIDUjCCAjqgAwIBAgIEUOLIQTANBg
> kqhkiG9w0BAQUFADBrMQswCQYDVQQGEwJGSTEQMA4GA1UE
> CBMHVXVzaW1hYTERMA8GA1UEBxMISGVsc2lua2kxGDAWBgNVBAoTD1JNNSBT
> b2Z0d2FyZSBPeTEM
> MAoGA1UECwwDUiZEMQ8wDQYDVQQDEwZhcG9sbG8wHhcNMTVQ49zRvi5qWNRttiFQ69FPcFDeEW
> bHwSoBy5hLPNALaEUoa5zPDwlixwRjFQTc5XXaRpgIjy/2gsL8+
> Y5QRhyXnLqgO67BlLYW/GuHE=</ds:X509Certificate></ds:X509Data>
> </ds:KeyInfo></md:KeyDescriptor><md:KeyDescriptor
> use="encryption"><ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#
> "><ds:X509Data><ds:X509Certificate>MIIDUjCCAjqgAwIBAgIEUOLIQTANBg
> kqhkiG9w0BAQUFADBrMQswCQYDVQQGEwJGSTEQMA4GA1UE
> CBMHVXVzaW1hYTERMA8GA1UEBxMISGVsc2lua2kxGDAWBgNVBAoTD1JNNSBT
> b2ZFQ69FPcFDeEW
> bHwSoBy5hLPNALaEUoa5zPDwlixwRjFQTc5XXaRpgIjy/2gsL8+
> Y5QRhyXnLqgO67BlLYW/GuHE=</ds:X509Certificate></ds:X509Data>
> </ds:KeyInfo></md:KeyDescriptor><md:SingleLogoutService
> Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="
> https://shibboleth-sp-xxxxx.com/shibboleth-sp/saml/SingleLogout"/><md:SingleLogoutService
> Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="
> https://shibboleth-sp-xxxxx.com/shibboleth-sp/saml/SingleLogout"/><md:
> NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:
> emailAddress</md:NameIDFormat><md:NameIDFormat>urn:oasis:
> names:tc:SAML:2.0:nameid-format:transient</md:
> NameIDFormat><md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:
> nameid-format:persistent</md:NameIDFormat><md:NameIDFormat>
> urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified</md:
> NameIDFormat><md:NameIDFormat>urn:oasis:names:tc:SAML:1.1:
> nameid-format:X509SubjectName</md:NameIDFormat><md:AssertionConsumerService
> Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="
> https://shibboleth-sp-xxxxx.com/shibboleth-sp/saml/SSO" index="0"
> isDefault="true"/><md:AssertionConsumerService
> Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="
> https://shibboleth-sp-xxxxx.com/shibboleth-sp/saml/SSO" index="1"/></md:
> SPSSODescriptor></md:EntityDescriptor>
>
> ---------------------------------------
>
> Please help. Many thanks.
>
>
> Snahasish
>
>
> On Mon, Nov 20, 2017 at 9:26 PM, David Huebner <david.huebner at daasi.de>
> wrote:
>
>> Since you are masking all the relevant URLs please make sure that the
>> entityID in the metadata exactly matches the one you try to initiate SSO
>> with.
>>
>> Oh and you probably have to URL-encode the entityID when requesting SSO.
>>
>> Refer to the examples in https://wiki.shibboleth.net/co
>> nfluence/display/IDP30/UnsolicitedSSOConfiguration
>>
>>
>>
>> On 20.11.2017 15:52, Santu Ghosh wrote:
>>
>> Hi David,
>>
>> Thanks for your response.
>>
>> - you did not register the SP in your IdP (i.e. load metadata of the SP)
>> This is working fine if we test SP initiated flow
>>
>> -the entityID in your URL does not match the entityID in the metadata file
>> - you did add the metadata but forgot to reload the
>> MetadataResolverService (or just restart Tomcat/Jetty)
>>
>> We have done above mentioned two steps every time when we made any
>> changed (if necessary) in xml.
>>
>>
>> Our IDP metadata looks like :
>>
>> <EntityDescriptor xmlns="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="
>> http://www.w3.org/2000/09/xmldsig#" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0"
>> xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" entityID="
>> https://idp.xxxxxxxx.com/idp/shibboleth">
>>
>>
>> And SP metadata looks like :
>>
>>
>> <?xml version="1.0" encoding="UTF-8"?><md:EntityDescriptor
>> xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata"
>> ID="https___shibboleth-sp.xxxxxxx.com_shibboleth-sp" entityID="
>> https://shibboleth-sp.xxxxxxxx.com/shibboleth-sp"><ds:Signature
>> xmlns:ds="http://www.w3.org/2000/09/xmldsig#"><ds:SignedInfo><ds:CanonicalizationMethod
>> Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/><ds:SignatureMethod
>> Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/><ds:Reference
>> URI="#https___shibboleth-sp.xxxxxxx.com_shibboleth-sp"><ds:Transforms><ds:Transform
>> Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/><ds:Transform
>> Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/></ds:Transforms><ds:DigestMethod
>> Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/><ds:Dige
>> stValue>OreU/14CANZdlXlhfpOdBwvjv3E=</ds:DigestValue></ds:
>> Reference></ds:SignedInfo><ds:SignatureValue>I0g7LWoPmja4lyu/9H
>>
>>
>> Can you please take a look.
>>
>> Snahasish
>>
>>
>>
>>
>> --
>> For Consortium Member technical support, see
>> https://wiki.shibboleth.net/confluence/x/coFAAg
>> To unsubscribe from this list send an email to
>> users-unsubscribe at shibboleth.net
>>
>
>
>
> --
> Snahasish Ghosh
> System Engineer.
> Mobile No- (0)9733960336
>
--
Snahasish Ghosh
System Engineer.
Mobile No- (0)9733960336
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20171122/3b7ccb9e/attachment-0001.html>
More information about the users
mailing list