Help setting up Shib's 3.4.3 Built-in CAS Server for Banner Apps
Pablo Vidaurri
psvidaurri at gmail.com
Thu Feb 14 11:16:35 EST 2019
*I also don’t see my employeeNumber anywhere in the logs *
*you are attempting to release via the filters config, but have resolved it
first from a datasource in your resolver config?*
On Thu, Feb 14, 2019 at 8:22 AM Melvin Lasky <melvin.lasky at manhattan.edu>
wrote:
> Hey everyone,
> I’m new to Shibboleth and we are trying to abandon our Ellucian Ethos
> Identity and go straight Shibboleth [for many reasons].
>
> We are using the docker container version of Shibboleth provided by
> Internet2 so that it’s all set up for InCommon Federation and everything. I
> have it successfully running on Google Kubernetes Engine, and I have a test
> SP running also on GKE and am able to log in and test it.
>
> Now, on to the real stuff. We are a Banner institution. I would like to
> use Shibboleth’s built in CAS Server, however, I can’t seem to figure it
> out. Our UDC_IDENTIFIER is stored as employeeNumber in LDAP. I see that
> in attribute-resolver.xml
>
> In my cas-protocol.xml I have this:
>
> <bean
> class="net.shibboleth.idp.cas.service.ServiceDefinition"
> c:regex="https://
> ([A-Za-z0-9_-]+\.)*manhattan\.edu(:\d+)?/.*"
> p:group="manhattan-college"
> p:authorizedToProxy="false" />
>
> And I am able to log into let’s say a Banner 9 app. However, upon logging
> in I am greeted with this message:
>
> System is configured for external authentication and identity assertion is
> null
>
> So then I set up this RelyingPartyOverrides:
>
> <bean id="shibboleth.regexRelyingParty" parent="RelyingParty" >
> <property name="activationCondition" >
> <bean
> class="net.shibboleth.idp.profile.logic.RelyingPartyIdPredicate" >
> <constructor-arg name="pred" >
> <bean class="com.google.common.base.Predicates"
> factory-method="or" >
> <constructor-arg>
> <util:list>
> <bean
> class="com.google.common.base.Predicates" factory-method="containsPattern"
> c:_0="
> https://ourappservers.*\.manhattan\.edu/.*" />
> </util:list>
> </constructor-arg>
> </bean>
> </constructor-arg>
> </bean>
> </property>
> <property name="profileConfigurations">
> <list>
> <ref bean="CAS.LoginConfiguration" />
> <ref bean="CAS.ProxyConfiguration" />
> <bean parent="CAS.ValidateConfiguration"
> p:userAttribute="employeeNumber" />
> </list>
> </property>
> </bean>
>
> Now I get:
>
> HTTP Status 403 - No assertions found.
>
> type Status report
>
> message No assertions found.
>
> description Access to the specified resource has been forbidden.
>
> Also this is now in the logs:
>
> shib-idp;idp-process.log;dev;nothing;2019-02-14 14:17:31,834 - ERROR
> [net.shibboleth.idp.cas:-2] - Uncaught runtime exception
> shib-idp;idp-process.log;dev;nothing;java.lang.IllegalStateException:
> Principal cannot be null
> shib-idp;idp-process.log;dev;nothing; at
> net.shibboleth.idp.cas.flow.impl.PrepareTicketValidationResponseAction.doExecute(PrepareTicketValidationResponseAction.java:101)
> shib-idp;idp-warn.log;dev;nothing;2019-02-14 14:17:31,834 - ERROR
> [net.shibboleth.idp.cas:-2] - Uncaught runtime exception
> shib-idp;idp-warn.log;dev;nothing;java.lang.IllegalStateException:
> Principal cannot be null
> shib-idp;idp-warn.log;dev;nothing; at
> net.shibboleth.idp.cas.flow.impl.PrepareTicketValidationResponseAction.doExecute(PrepareTicketValidationResponseAction.java:101)
>
> ———————
>
> I also have this in my attribute-filter.xml
>
> <AttributeFilterPolicy id="releaseForBannerApps" >
> <PolicyRequirementRule xsi:type="RequesterRegex"
> regex="https:\/\/ourappservers.*\.manhattan\.edu" />
> <AttributeRule attributeID="employeeNumber">
> <PermitValueRule xsi:type="ANY" />
> </AttributeRule>
> </AttributeFilterPolicy>
>
>
> —————————————————————————————————————————
>
> Also - our Banner App Servers are looking for the claim UDC_IDENTIFIER….
> But I can change that to whatever if I have to. Or whatever I need.
>
> Any suggestions on how we could get this to work would be awesome? I’m
> really at a loss.
>
> I also don’t see my employeeNumber anywhere in the logs
>
> Thank you for any help you can provide!
>
> Have a great day!
>
> Mel
>
> *Melvin Lasky*
> *Associate Director of Enterprise Architecture*
>
>
>
>
> Riverdale, NY 10471
> Phone: 718-862-7410
> melvin.lasky at manhattan.edu
> www.manhattan.edu
>
>
>
>
> --
> For Consortium Member technical support, see
> https://wiki.shibboleth.net/confluence/x/coFAAg
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20190214/54beae12/attachment.html>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: email_logo.jpg
Type: image/jpeg
Size: 7478 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/users/attachments/20190214/54beae12/attachment.jpg>
More information about the users
mailing list