SP generated AssertionConsumerServiceURL not https

Altgilbers, Ian M Ian.Altgilbers at tufts.edu
Fri Oct 26 15:59:06 EDT 2018


I am setting up a new RHEL7 server  with apache 2.4 and:
shibboleth-3.0.2-1.1.x86_64

I configured my shibboleth2.xml config file like I have on several other hosts (with shibboleth 2.x), but when I go to collect my SP metadata to provide to our IdP admins, all the the AssertionConsumerService Locations are http, instead of https.

Apache is only listening on port 80 in order to redirect to 443…  I have been able to get around this by having Apache do a 307 redirect to https, but that’s masking the problem.

I’ve tried setting the attribute:  allowedSchemes=“https” in <SPConfig>, but it didn’t seem to have any effect.

I tried manually updating the SP metadata with https urls.  Then, when I try to login, the AuthnRequest that the SP generates uses http:// for AssertionConsumerServiceURL, so the IdP can’t find a match and rejects me.


What could I be missing?   Why would the SP’s metadata generator be producing http:// URLs?   I’m accessing the SP over https...


Thanks,



Ian Altgilbers
Senior Systems Administrator
Educational Technology Services
Tufts Technology Services
Tufts University

Phone: 617.627.0388
http://it.tufts.edu/ests

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20181026/fd7e89dc/attachment.html>


More information about the users mailing list