Apache Shibboleth SP Stuck at /Shibboleth.sso/SAML2/POST after IDP login
Ignacio Amoeiro Bosch
ignacio.amoeiro at extern.ssib.es
Mon Jun 9 13:49:50 UTC 2025
Hi,
Already have checked that, SELinux is disables.
[root at XXXXXXX httpd]# getenforce
Disabled
Thanks for the suggestion.
Anyones, only stucks requests to SAML endpoints /Shibboleth.sso/SAML2/POST) .
If I try Metadata or Status, it Works. Also if I do a request to a wrong endpoint /Shibboleth.sso/SAML2/PO , it replies with an shibd error, so communication with shibd is working I guess.
Regarrds
De: Steven Premeau <steven.premeau at maine.edu>
Enviado el: lunes, 9 de junio de 2025 15:22
Para: Shib Users <users at shibboleth.net>
CC: Ignacio Amoeiro Bosch <ignacio.amoeiro at extern.ssib.es>
Asunto: Re: Apache Shibboleth SP Stuck at /Shibboleth.sso/SAML2/POST after IDP login
Aquest e-mail prové d'un remitent extern al IB-Salut. No faci clic en enllaços ni obri arxius adjunts, si no confia en l'emissor.
Este e-mail proviene de un remitente externo al IB-Salut. No haga clic en enlaces ni abra archivos adjuntos, si no confía en el remitente.
Is SELinux set to 'enforcing' on the system?
By default SELinux will prevent the communication between httpd and shibd on an "out of the box" RHEL system.
See https://shibboleth.atlassian.net/wiki/spaces/SP3/pages/2065335559/SELinux<https://ddec1-0-en-ctp.trendmicro.com:443/wis/clicktime/v1/query?url=https%3a%2f%2fshibboleth.atlassian.net%2fwiki%2fspaces%2fSP3%2fpages%2f2065335559%2fSELinux&umid=9ddcde70-64fb-48cb-bb5b-db396d87ffd1&rct=1749475316&auth=a519943a12ceb2e36c49780f98de389ccf711159-2bed8409031eff6bc516665d0fda3aa4550c70d9> for more information.
If it is enforcing, and you do not want to disable enforcement, you can follow the link on the page above or you can google "selinux mod_shib-to-shibd" for (unsupported) examples of what might be required to allow the communication between the two processes.
Steve.
On Mon, Jun 9, 2025 at 3:15 AM Ignacio Amoeiro Bosch via users <users at shibboleth.net<mailto:users at shibboleth.net>> wrote:
Hi,
I forgot to say, on server-status page all requests to /Shibboleth.sso/SAML2/POST are in W state (Sending Repply)
Regards
-----Mensaje original-----
De: users <users-bounces at shibboleth.net<mailto:users-bounces at shibboleth.net>> En nombre de Ignacio Amoeiro Bosch via users
Enviado el: lunes, 9 de junio de 2025 8:32
Para: Shib Users <users at shibboleth.net<mailto:users at shibboleth.net>>
CC: Ignacio Amoeiro Bosch <ignacio.amoeiro at extern.ssib.es<mailto:ignacio.amoeiro at extern.ssib.es>>
Asunto: Apache Shibboleth SP Stuck at /Shibboleth.sso/SAML2/POST after IDP login
Aquest e-mail prové d'un remitent extern al IB-Salut. No faci clic en enllaços ni obri arxius adjunts, si no confia en l'emissor.
Este e-mail proviene de un remitente externo al IB-Salut. No haga clic en enlaces ni abra archivos adjuntos, si no confía en el remitente.
Hi Team,
After migrating from RH8 to RH9, we've come across something weird on a Shibboleth SP on Apache.
When we go to a protected resource ( /secure for example) we are being redirected to the IDP, and after login in, browser is stuck at /Shibboleth.sso/SAML2/POST without any error, it keeps there endless till browser timeout.
This happens after migrating from Redhat8 to Redhat 9.5 ( I have other servers with 9.5 + SP working fine)
Things I have tried:
- Shibboleth SP clean install (rpm removed + depedencies, deleted /etc/shibboleth, and reinstalled from rockylinux9 repo).
- Apache HTTPD clean install (rpm removed, deleted /etc/httpd, and reinstalled)
Firewall is disabled
Antivirus disabled
As I said, the http request is not getting answered so, I can't see any error on apache logs or shibd logs.
Apache httpd process are 100% CPU after I do the first request to /Shibboleth.sso/SAML2/POST endpoint.
Every other public pages are working fine.
I tried to set some loggers in apache or shibd to debug, but can't see anything relevant.
And the worst, i don't see any error on apache logs or shibd logs.
Any idea?
Thanks.
--
For Consortium Member technical support, see https://ddec1-0-en-ctp.trendmicro.com:443/wis/clicktime/v1/query?url=https%3a%2f%2fshibboleth.atlassian.net%2fwiki%2fx%2fZYEpPw&umid=7e0aa5fa-9b7b-4ccf-8274-33175af8f15c&rct=1749450716&auth=a519943a12ceb2e36c49780f98de389ccf711159-7297fa116f9e2d20ae4856c4157299ace4b8c8e5
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net<mailto:users-unsubscribe at shibboleth.net>
--
For Consortium Member technical support, see https://shibboleth.atlassian.net/wiki/x/ZYEpPw<https://ddec1-0-en-ctp.trendmicro.com:443/wis/clicktime/v1/query?url=https%3a%2f%2fshibboleth.atlassian.net%2fwiki%2fx%2fZYEpPw&umid=9ddcde70-64fb-48cb-bb5b-db396d87ffd1&rct=1749475316&auth=a519943a12ceb2e36c49780f98de389ccf711159-58cae741228479e83cb61ef498fe6c6cc74bb20c>
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net<mailto:users-unsubscribe at shibboleth.net>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20250609/9df05b55/attachment.htm>
More information about the users
mailing list