users Digest, Vol 77, Issue 108
Cheltenham, Chris
ccheltenham-ext at philasd.org
Tue Nov 28 14:46:08 EST 2017
Thank You Nate.
Appreciate it.
===========================
Thank You;
Chris Cheltenham
Technology Services
The School District of Philadelphia
Work # 215-400-5025
Cell # 215-301-6571
-----Original Message-----
From: users [mailto:users-bounces at shibboleth.net] On Behalf Of
users-request at shibboleth.net
Sent: Tuesday, November 28, 2017 2:43 PM
To: users at shibboleth.net
Subject: users Digest, Vol 77, Issue 108
Send users mailing list submissions to
users at shibboleth.net
To subscribe or unsubscribe via the World Wide Web, visit
http://shibboleth.net/mailman/listinfo/users
or, via email, send a message with subject or body 'help' to
users-request at shibboleth.net
You can reach the person managing the list at
users-owner at shibboleth.net
When replying, please edit your Subject line so it is more specific than
"Re: Contents of users digest..."
Today's Topics:
1. RE: reloading metadata (Klingenstein, Nate)
2. New metadata (Cheltenham, Chris)
3. Re: Unsolicited SSO with AuthnRequestsSigned="true" SP
metadata (Santu Ghosh)
4. RE: New metadata (Klingenstein, Nate)
----------------------------------------------------------------------
Message: 1
Date: Tue, 28 Nov 2017 19:28:25 +0000
From: "Klingenstein, Nate" <nklingenstein at calstate.edu>
To: Shib Users <users at shibboleth.net>
Subject: RE: reloading metadata
Message-ID:
<MWHPR01MB22228E1D147B2ECF052F5059DE3A0 at MWHPR01MB2222.prod.exchangelabs.co
m>
Content-Type: text/plain; charset="us-ascii"
Chris,
> What is the difference between /opt/shib/bin/reload-metadata.sh
There is no functional difference between them other than the invocation
method, so far as I'm aware.
> Also, Can I regenerate the IDP's metadata using keygen.sh under the bin
directory.
No. That would only generate new keys for you, which you don't want. The
metadata generated on first install is meant to be a starting template for
you. You can modify it at /opt/shib/metadata/idp-metadata.xml.
Thanks,
Nate.
------------------------------
Message: 2
Date: Tue, 28 Nov 2017 14:40:33 -0500 (EST)
From: "Cheltenham, Chris" <ccheltenham-ext at philasd.org>
To: <users at shibboleth.net>
Subject: New metadata
Message-ID: <00ab01d36880$c1724370$4456ca50$@philasd.org>
Content-Type: text/plain; charset="us-ascii"
Hello,
My metadata was inherited and seems to work fine.
However it has multiple certificates in there.
Why are there so many certificates and can I create new metadata with only
one certificate?
IDP 3.2.1
===========================
Thank You;
Chris Cheltenham
Technology Services
The School District of Philadelphia
Work # 215-400-5025
Cell # 215-301-6571
-------------- next part --------------
An HTML attachment was scrubbed...
URL:
<http://shibboleth.net/pipermail/users/attachments/20171128/90b798f2/attac
hment-0001.html>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image001.gif
Type: image/gif
Size: 1089 bytes
Desc: not available
URL:
<http://shibboleth.net/pipermail/users/attachments/20171128/90b798f2/attac
hment-0001.gif>
------------------------------
Message: 3
Date: Wed, 29 Nov 2017 01:11:08 +0530
From: Santu Ghosh <mon.snahasish at gmail.com>
To: Shib Users <users at shibboleth.net>
Subject: Re: Unsolicited SSO with AuthnRequestsSigned="true" SP
metadata
Message-ID:
<CAEi_2y2c7CuH0-TteqOWTtZ6MCMvTBVFgUxJM2dER9gPLZrfZg at mail.gmail.com>
Content-Type: text/plain; charset="utf-8"
Thanks Peter?,
I understand your concern. But very sorry to say I have no control here.
As I understand, I have to remove that attribute from sp metadata to use
unsolicited sso.
On Wed, Nov 29, 2017 at 12:32 AM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> > By policy, we will use only IDP initiated flow. In that case I have
> > to
> remove
> > the XML attribute from SP metadata (as only solution).
>
> This "policy" isn't enforced by the IdP, which makes it a waste of time.
> If you did want to enforce it, you would have to make very low level
> changes that you don't know how to make and that we don't support.
>
> -- Scott
>
> --
> For Consortium Member technical support, see
> https://wiki.shibboleth.net/ confluence/x/coFAAg To unsubscribe from
> this list send an email to users-unsubscribe at shibboleth.net
>
--
Snahasish
-------------- next part --------------
An HTML attachment was scrubbed...
URL:
<http://shibboleth.net/pipermail/users/attachments/20171129/2876d1c4/attac
hment-0001.html>
------------------------------
Message: 4
Date: Tue, 28 Nov 2017 19:43:20 +0000
From: "Klingenstein, Nate" <nklingenstein at calstate.edu>
To: Shib Users <users at shibboleth.net>
Subject: RE: New metadata
Message-ID:
<MWHPR01MB222285AE4AD516FC15752EFCDE3A0 at MWHPR01MB2222.prod.exchangelabs.co
m>
Content-Type: text/plain; charset="us-ascii"
Chris,
Nobody can tell you if your metadata is accurate or what it should
contain. It describes your deployment. That file might not even be
loaded by your partners; I would check your logs to see if it's used.
Multiple keys are typically used for key rollover or attribute queries.
You should modify the metadata to match your configuration. If you're
using one certificate, then put that one certificate in.
Thanks,
Nate.
------------------------------
Subject: Digest Footer
--
For Consortium Member technical support, see
https://wiki.shibboleth.net/confluence/x/coFAAg
To unsubscribe from this list send an email to
users-unsubscribe at shibboleth.net
------------------------------
End of users Digest, Vol 77, Issue 108
**************************************
More information about the users
mailing list