Ignore a Specific Subject Confirmation Support

Muhammad Farhan SJAUGI farhan at sifulan.my
Mon Oct 16 23:29:12 UTC 2023


Hi,

I am trying to set up shibboleth idp as an idp proxy to CAS server and use
SAML protocol as the authentication protocol between the shibboleth idp
(proxy) and the CAS server. However, due SubjectConfirmationData/@Address
was resolved to some addresses that mismatched any supplied valid
addresses, hence the authentication was failed. For better understanding of
the situation, the shibboleth idp is installed as a kubernetes container,
while the CAS server is installed as a standalone server. The kubernetes
resolves the shibboleth idp's domain name to an external dns server, while
the shibboleth idp detects the address from some Kubernetes' internal ip
address.

My question is, can we configure the shibboleth idp to ignore a specific
Subject Confirmation support? (i.e. ignore the
SubjectConfirmationData/@Address)

I also noticed that there's such an option to not request for subject
confirmation by using address on CAS, however it didn't work despite I had
enabled/configured it.

Any feedback or clue is greatly appreciated.

Thank you
--
*Ts. Muhammad Farhan Sjaugi, S.Kom. M.Sc.*

*VP (Engineering and Services)*
SIFULAN Malaysian Access Federation
Email: farhan at sifulan.my | Website: https://www.sifulan.my
PGP Fingerprint: 9AA0 1861 0921 3EBD 4E30 716A 1F71 FC55 49CD D06C
MBOT: GT20040131 |  ORCID: https://orcid.org/0000-0001-8497-1768
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20231017/8138095d/attachment.htm>


More information about the users mailing list