Help setting up Shib's 3.4.3 Built-in CAS Server for Banner Apps
Marvin Addison
serac at vt.edu
Thu Feb 14 14:20:29 EST 2019
On Thu, Feb 14, 2019 at 2:10 PM Melvin Lasky <melvin.lasky at manhattan.edu>
wrote:
> <AttributeFilterPolicy id="releaseForBannerApps" >
> <PolicyRequirementRule xsi:type="Requester" value="
> https://specific_banner_app_server.manhattan.edu" />
>
If you register services via the CAS service registry, then the relying
party ID will be _exactly_ the value sent to the IdP in the "service" CAS
protocol parameter. I suspect that's the problem here given that the URL
above has no path or query parts. Look at the traffic between your Banner
apps and Shib using your browser's developer console to capture the exact
service URL that's getting sent to Shib, then update your attribute filter
rule accordingly.
Hope that helps,
Marvin
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20190214/e69ceba2/attachment.html>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: email_logo.jpg
Type: image/jpeg
Size: 7478 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/users/attachments/20190214/e69ceba2/attachment.jpg>
More information about the users
mailing list