Shibboleth SP for multiple domains
vadud3 at gmail.com
vadud3 at gmail.com
Wed Jul 7 18:07:37 UTC 2021
On Wed, Jul 7, 2021 at 5:37 AM Peter Schober <peter.schober at univie.ac.at>
wrote:
>
> * vadud3 at gmail.com <vadud3 at gmail.com> [2021-07-06 23:19]:
> > We’ve tried following the following two links / options, but couldn’t
> > get it working:
> >
> > https://wiki.cac.washington.edu/pages/viewpage.action?pageId=61703128
> >
> > https://wiki.cac.washington.edu/pages/viewpage.action?pageId=28939166
> [...]
> > We are looking to see if we are going down the right path. Which
> > option should we be trying to complete? Should we be trying to do
> > this under 1 entityID or use separate entityIDs for each site that we
> > have?
>
> 1. Contrary to popular belief "couldn't get it working" is not a
> technical error description that would enable anyone to help you solve
> your problem.
>
> 2. Those instructions are not from the official software documentation
> (which doesn't mean they're bad) and expecting people to read 3rd
> party documentation only to help you fix a problem you haven't even
> described is asking a bit much, IMO.
>
> 3. Only you can know whether one entityID will suffice for your use
> case or not. Of course you also don't mention anything about the
> number or kind of services so it's impossible for anyone else to say.
> Follwing Occam's razor a single one should suffice unless you *know*
> your use case requires multiple.
> (If the IDPs need to be able to differentiate those logical SPs in
> order to apply differing policies then you'll likely need multiple
> entityIDs for the logical SPs. If you can get away without that avoid
> it, of course.)
>
> -peter
> --
> For Consortium Member technical support, see
https://wiki.shibboleth.net/confluence/x/coFAAg
> To unsubscribe from this list send an email to
users-unsubscribe at shibboleth.net
I have a cluster of jira application nodes behind a set of proxy servers
running apache 2.4. These proxy servers
are also setup as SP providers
Here is the current relevant config (sanitized)
node1-vhost.conf
=============
<Location /jira>
<If "%{REQUEST_URI} =~ m#^/(jira/server-info|jira/s/).*#">
Satisfy Any
</If>
<If "%{REQUEST_URI} =~ m#^/jira/rest/collectors/.*#">
RequestHeader set X-Atlassian-Token nocheck
</If>
Order allow,deny
Allow from all
AuthType Shibboleth
Header set X-Forwarded-Proto "https"
ShibUseHeaders On
ShibRequestSetting requireSession true
*ShibRequestSetting applicationId node1*
<RequireAny>
Require shib-attr AuthType "standard, x509, securePlus2, securePlus3,
piv"
Require shib-attr AppAuth true
Require shib-attr idp https://sts.example.net/76c-94d-4a2-bb7a-2354a/
</RequireAny>
</Location>
discovery file shibboleth-ds.conf
=========================
<IfModule mod_alias.c>
<Location /shibboleth-ds>
Allow from all
<IfModule mod_shib.c>
AuthType shibboleth
ShibRequestSetting requireSession false
require shibboleth
</IfModule>
</Location>
Alias /shibboleth-ds/idpselect_config.js
/etc/shibboleth-ds/idpselect_config.js
Alias /shibboleth-ds/idpselect.js /etc/shibboleth-ds/idpselect.js
Alias /shibboleth-ds/idpselect.css /etc/shibboleth-ds/idpselect.css
Alias /shibboleth-ds/index.html /etc/shibboleth-ds/index.html
Alias /shibboleth-ds/blank.gif /etc/shibboleth-ds/blank.gif
</IfModule>
shibboleth2.xml (note: server.example.org is cluster front end)
===============================================
<ApplicationDefaults id="default" entityID="https://server.example.org"
REMOTE_USER="nameid eppn uid persistent-id targeted-id"
signing="true" encryption="true">
<Sessions lifetime="28800" timeout="1800" relayState="ss:mem"
checkAddress="false" consistentAddress="false"
handlerSSL="true" cookieProps="https">
<SSO discoveryProtocol="SAMLDS" discoveryURL="
https://server.example.org/shibboleth-ds/index.html">
SAML2 SAML1
</SSO>
<Logout>SAML2 Local</Logout>
<Handler type="MetadataGenerator" Location="/Metadata"
signing="false"/>
......
</Sessions>
<*ApplicationOverride id="node1"
entityID="https://node1.example.org <https://node1.example.org>"*/>
<ApplicationOverride id="node2" entityID="
https://node2.example.org"/>
<ApplicationOverride id="node3" entityID="
https://node3.example.org"/>
</ApplicationDefaults>
I can get to https://server.example.org/jira and authentication works fine.
saml request for server
<samlp:AuthnRequest xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"
AssertionConsumerServiceURL="
https://server.example.org/Shibboleth.sso/SAML2/POST" Destination="
https://ssotest.example.org/adfs/ls/"
ID="_8b4283a72909133856ada1a3c3e61118" IssueInstant="2021-07-07T17:25:34Z"
ProtocolBinding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"
Version="2.0">
<saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">
https://server.example.org</saml:Issuer>
<samlp:NameIDPolicy AllowCreate="1"/>
</samlp:AuthnRequest>
But I am failing when I try to connect to https://node1.example.org/jira.
It gives me an (I think from IdP) error saying an error orrcured and
provides some parameters in error
details like Activity ID, Relying party, User agent string, etc.
saml request for node1
<samlp:AuthnRequest xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"
AssertionConsumerServiceURL="
https://node1.example.org/Shibboleth.sso/SAML2/POST" Destination="
https://ssotest.example.org/adfs/ls/"
ID="_a672076156126c72dfe845759e79a7e7" IssueInstant="2021-07-07T17:10:41Z"
ProtocolBinding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"
Version="2.0">
<saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">
https://server.example.org</saml:Issuer>
<samlp:NameIDPolicy AllowCreate="1"/>
</samlp:AuthnRequest>
Looking for some help to troubleshoot this.
--
Asif Iqbal
PGP Key: 0xE62693C5 KeyServer: pgp.mit.edu
A: Because it messes up the order in which people normally read text.
Q: Why is top-posting such a bad thing?
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20210707/824daf65/attachment.htm>
More information about the users
mailing list