[EXTERNAL] Re: Setting shibboleth/apache behind nginx reverse proxy
nicolas roggli
nicolas.roggli at unige.ch
Mon Dec 18 14:40:31 UTC 2023
Hi Pascal,
Thank you very much, as far as I can tell, that did it. I set the
handlerSSL back to true, no more error, and I could authenticate.
Le 18.12.23 à 14:42, Pascal Rigaux via users a écrit :
> Hi
>
> Here is what we do in Apache conf:
>
> ServerName https://xxxx:443
>
>
> Ref: https://httpd.apache.org/docs/2.4/en/mod/core.html#servername
>
> « Sometimes, the server runs behind a device that processes SSL, such
> as a reverse proxy, load balancer or SSL offload appliance. When this
> is the case, specify the https:// scheme and the port number to which
> the clients connect in the ServerName directive to make sure that the
> server generates the correct self-referential URLs. »
>
> cu
>
>
> On 15/12/2023 15:51, nicolas roggli via users wrote:
>> Hi,
>>
>> I am trying to setup a shibboleth/apache authentication behind an
>> nginx server. Here below are my current nginx and apache config, I
>> just changed the domain names.
>>
>> I am quite confident that nginx passes the requests to apache. When I
>> access https://services.mydomain.ch, it reaches the file defined in
>> the apache config (/var/www/staging/proxied/index.html) which is
>> different from the root defined in the nginx config.
>>
>> Accessing https://services.mydomain.ch/secure does try to
>> authenticate, as I receive an expected message stating
>>
>> > Unknown or Unusable Identity Provider
>> >
>> > The identity provider supplying your login credentials is not
>> authorized for use with this service or does not support the
>> necessary capabilities.
>>
>> My problem, or one of, is that I cannot access
>> https://services.mydomain.ch/Shibboleth.sso/Session which results in
>> a 404 error. Apache logs the access, but no error except the 404.
>> 127.0.0.1 - - [15/Dec/2023:15:33:03 +0100] "GET
>> /Shibboleth.sso/Session HTTP/1.0" 404 .....
>>
>> Any idea why I can't access /Shibboleth.sso/Session ?
>>
>> Any suggestions are welcomed and would be greatly appreciated
>>
>> Nicolas
>>
>> ----------------- nginx -----------------
>> server {
>>
>> listen 80;
>> listen [::]:80;
>>
>> server_name services.mydomain.ch;
>> if ($host = services.mydomain.ch) {
>> return 301 https://$host$request_uri;
>> }
>> }
>>
>> server {
>> listen 443 ssl;
>> listen [::]:443 ssl;
>>
>> server_name services.mydomain.ch;
>> root /var/www/staging/test;
>>
>> access_log /var/log/nginx/services-access.log;
>> error_log /var/log/nginx/services-error.log;
>>
>> index index.html;
>>
>> location / {
>> proxy_set_header Host $host;
>> proxy_set_header X-Forwarded-Host $host:$server_port;
>> proxy_set_header X-Forwarded-Server $host;
>> proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
>> proxy_pass http://127.0.0.1:8081;
>> }
>>
>> location ~ /\.git {
>> deny all;
>> }
>>
>> ssl_certificate
>> /etc/letsencrypt/live/services.mydomain.ch/fullchain.pem; # managed
>> by Certbot
>> ssl_certificate_key
>> /etc/letsencrypt/live/services.mydomain.ch/privkey.pem; # managed by
>> Certbot
>> }
>>
>> ----------------- apache -----------------
>>
>> <VirtualHost *:8081>
>> ServerAdmin webmaster at localhost
>> DocumentRoot /var/www/staging/proxied
>> <Location "/secure">
>> AuthType shibboleth
>> ShibRequestSetting entityID
>> http://adfs.mydomain.ch/adfs/services/trust
>> ShibRequestSetting requireSession true
>> ShibUseHeaders On
>> Require shibboleth
>> Require valid-user
>> </Location>
>>
>> ErrorLog ${APACHE_LOG_DIR}/services-error.log
>> CustomLog ${APACHE_LOG_DIR}/services-access.log combined
>> </VirtualHost>
>>
>
More information about the users
mailing list