No keys generated when installing SP 3.0.2
Reuscher, Robert
rreuscher at utsystem.edu
Tue Oct 9 19:04:58 EDT 2018
Right, we've upgraded some test servers and came across that. Someone else did the first upgrades, he didn't use our scripts since it was an upgrade. I did the first new installs with our scripts which uses our template for the shibboleth2.xml. I've just updated that to reflect what we need for V3 and was able to complete the install and get the daemon running.
-----Original Message-----
From: users <users-bounces at shibboleth.net> On Behalf Of Lipscomb, Gary
Sent: Tuesday, October 9, 2018 5:52 PM
To: Shib Users <users at shibboleth.net>
Subject: RE: No keys generated when installing SP 3.0.2
** External Mail **
Note that if you upgrade from an existing v2 SP install to v3 SP the existing key file pair /etc/shibboleth/sp-cert.pem and /etc/shibboleth/sp- key.pem do not change, and the new key pairs for signing and encryption are not created.
Gary
-----Original Message-----
From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Reuscher, Robert
Sent: Wednesday, 10 October 2018 08:36
To: Shib Users <users at shibboleth.net>
Subject: RE: No keys generated when installing SP 3.0.2
We run Shibboleth on a lot of servers, and have been installing it on many more servers over the last year. All of the have basically the same /etc/shibboleth/shibboleth2.xml file with our customizations. The only difference is the url for the local system. So have some scripts that runs during the installation that copies our customized shibboleth2.xml file and changes a fixed string for the url to the url for for that particular system. I just needed to update the template file we use in that process changing the <CredentialResolver> statements to point to the new key files. Along with a few other minor modifications for other parameter changes between V2 and V3.
-----Original Message-----
From: users <users-bounces at shibboleth.net> On Behalf Of Lipscomb, Gary
Sent: Tuesday, October 9, 2018 4:23 PM
To: Shib Users <users at shibboleth.net>
Subject: RE: No keys generated when installing SP 3.0.2
** External Mail **
The files created from a clean install of shibboleth-sp v3 on RHEL 7 are a signing and an encryption key pair
-rw-r--r-- 1 shibd shibd 1484 Sep 26 14:35 sp-encrypt-cert.pem
-rw------- 1 shibd shibd 2484 Sep 26 14:35 sp-encrypt-key.pem
-rw-r--r-- 1 shibd shibd 1484 Sep 26 14:35 sp-signing-cert.pem
-rw------- 1 shibd shibd 2484 Sep 26 14:35 sp-signing-key.pem
https://wiki.shibboleth.net/confluence/display/SP3/Multiple+Credentials
Regards
Gary
-----Original Message-----
From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Cantor, Scott
Sent: Wednesday, 10 October 2018 03:44
To: Shib Users <users at shibboleth.net>
Subject: Re: No keys generated when installing SP 3.0.2
On 10/9/18, 12:41 PM, "users on behalf of Reuscher, Robert" <users-bounces at shibboleth.net on behalf of rreuscher at utsystem.edu> wrote:
> The install completes, but it does not create either the
> /etc/shibboleth/sp-cert.pem or the /etc/shibboleth/sp- key.pem files, so the shibd process won’t start. It fails trying to open the key file.
Those aren't the filenames used in a "from scratch" V3 install, the names are different and they match what the configuration would expect. And I can't imagine that it didn't generate them, but they won't be those two.
-- Scott
--
For Consortium Member technical support, see https://wiki.shibboleth.net/confluence/x/coFAAg
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
--
For Consortium Member technical support, see https://wiki.shibboleth.net/confluence/x/coFAAg
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
--
For Consortium Member technical support, see https://wiki.shibboleth.net/confluence/x/coFAAg
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
--
For Consortium Member technical support, see https://wiki.shibboleth.net/confluence/x/coFAAg
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list