WebLogic and SAML

Yeargan, Yancey Yancey.Yeargan at untsystem.edu
Wed Sep 30 21:16:32 UTC 2020


I wonder if someone may be willing to help us out. Our PeopleSoft team was asked to do a proof of concept for SSO. That team asked me for help with configuring the SAML part. I have plenty of experience with Apache and IIS, but have no previous experience with WebLogic.

We attempted to follow the Oracle WebLogic server docs here.

https://docs.oracle.com/en/middleware/fusion-middleware/weblogic-server/12.2.1.4/secmg/saml.html

We also referred to the following article.

https://medium.com/@donaldlika/single-sign-on-weblogic-configuration-service-provider-initiated-using-saml2-as-protocol-5af293f76321

We think we configured the WebLogic SAML SP properly. We did get a metadata file from it, and configured that in our Shibboleth Identity Provider. We also think we have the IdP configured in WebLogic, so that it should trust our IdP.

However, we have been unable to get WebLogic to intercept a web request -- to redirect the web browser to the IdP. Also, the WebLogic SP's Assertion Consumer Service URL returns an HTTP 404 response. I've tried IdP-initiated SSO, and get a 404 from WebLogic.

If we can get WebLogic to process a SAML authentication response and put the SAML attributes into HTTP request headers, we feel confident we can proceed from there.

I feel we are missing something obvious and just not seeing it. Is there some trick to get WebLogic to start functioning as a SAML service provider? Despite all our configuration, it seems to be waiting for Captain Picard to give the "Engage!" command.

I am aware this is not directly Shibboleth related, but we would be grateful if someone would be willing to point us in the correct direction.

Yancey Yeargan
IT Manager
IT Shared Services
________________________________
UNIVERSITY OF NORTH TEXAS SYSTEM
Office: 940.369.7521

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20200930/a4ae95d7/attachment.htm>


More information about the users mailing list