SP 3 and reverseProxy
Jehan PROCACCIA
jehan.procaccia at tem-tsp.eu
Mon Oct 29 11:16:30 EDT 2018
On 29/10/2018 14:07, Peter Schober wrote:
>
> You're reading old, contributed documentation on how to:
> "Deploy the Service Provider behind a Reverse Web Proxy"
> (i.e., the page's title).
> If you're not intending to deploy the Shib SP behind a reverse proxy
> (but have the web server with shib *be* the reverse proxy) you're
> simply reading the wrong documentation.
Yes I want the latter => "web server with shib *be* the reverse proxy" , in order not to have to deploy shib SP software and conf on each of individual SPs .
> While there's an even older page on the topic you're interested in
> https://wiki.shibboleth.net/confluence/display/SHIB/SPForwardProxy
> it's probably safe to ignore that.
this indeed describe what I want to do , but why should I ignore it ?, deprecated / old conf ?
is that "architecture" (factorizing SPs into a single proxy) is not recommended ?
will I have to create an application ovveride for on the proxy SP config for each of the web applications and then publish in the federation metadata endpoint for all the web appplications ?
before investing in it, I just want to be sure that it can be done and that it does saves me the burden tu publish many metadata files and specific configs for web applications that needs simple general federated authN.
I will also talk to my french collegue (Renater NREN) who apparently manages that kind of architecture.
regards .
----- Mail original -----
De: "Peter Schober" <peter.schober at univie.ac.at>
À: "users" <users at shibboleth.net>
Envoyé: Lundi 29 Octobre 2018 14:07:55
Objet: Re: SP 3 and reverseProxy
* Jehan PROCACCIA <jehan.procaccia at tem-tsp.eu> [2018-10-28 23:13]:
> The idea beeing to install,configure and publish metadata of a
> single shibboleth SP only for the reverseProxy and not on the all
> the multiple ressources web hosts.
>
> from
> https://wiki.shibboleth.net/confluence/display/SHIB2/SPReverseProxy
> it seems that while using a reverseProxy we still need to deploy
> shibboleth SP on the ressource server (web applications)
You're reading old, contributed documentation on how to:
"Deploy the Service Provider behind a Reverse Web Proxy"
(i.e., the page's title).
If you're not intending to deploy the Shib SP behind a reverse proxy
(but have the web server with shib *be* the reverse proxy) you're
simply reading the wrong documentation.
While there's an even older page on the topic you're interested in
https://wiki.shibboleth.net/confluence/display/SHIB/SPForwardProxy
it's probably safe to ignore that.
> I understand that serving hundreds of web apps behind a single
> reverseProxy will be a spof and a bottleneck , but for a dozen of
> web apps is it still possible ?
Sure. You protect a resource with httpd, whether that's a local file
or something else doesn't matter to httpd.
-peter
--
For Consortium Member technical support, see https://wiki.shibboleth.net/confluence/x/coFAAg
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list