Taking a look/trying enabling X509 Authentication in Shibboleth IdP

Steven Premeau steven.premeau at maine.edu
Thu May 22 18:01:17 UTC 2025


If there is a question of whether the WAR file is current, a rebuild
would (never) hurt -- twice is better than not at all.

Installing the module does not automatically make it part of the
login process.  Unless you are ONLY going to allow X509 certificate
authentication, you would need to configure the authn/MFA
<https://shibboleth.atlassian.net/wiki/spaces/IDP5/pages/3199505534/MultiFactorAuthnConfiguration>
flow to manage multiple authentication options.

Steve.

On Thu, May 22, 2025 at 1:30 PM o haya via users <users at shibboleth.net>
wrote:

> Hi,
>
> I want to try to enable X509 authentication on the Shibbleth IdP that I
> have, and I've tried to follow the information at:
>
>
> https://shibboleth.atlassian.net/wiki/spaces/IDP5/pages/3199506319/X509AuthnConfiguration#General-Configuration
>
> I've run the module command as described:
>
> bin/module.sh -t idp.authn.X509 || bin/module.sh -e idp.authn.X509
>
> and got:
>
> ./module.sh -t idp.authn.X509 || ./module.sh -e idp.authn.X509
>>
>> INFO  - Including auto-located properties in
>> ./../conf/admin/admin.properties
>>
>> INFO  - Including auto-located properties in
>> ./../conf/authn/authn.properties
>>
>> INFO  - Including auto-located properties in
>> ./../conf/c14n/subject-c14n.properties
>>
>> INFO  - Including auto-located properties in
>> ./../conf/saml-nameid.properties
>>
>> INFO  - Including auto-located properties in
>> ./../conf/services.properties
>>
>> INFO  - Including auto-located properties in ./../conf/ldap.properties
>>
>> INFO  - Including auto-located properties in
>> ./../conf/admin/admin.properties
>>
>> INFO  - Including auto-located properties in
>> ./../conf/authn/authn.properties
>>
>> INFO  - Including auto-located properties in
>> ./../conf/c14n/subject-c14n.properties
>>
>> INFO  - Including auto-located properties in
>> ./../conf/saml-nameid.properties
>>
>> INFO  - Including auto-located properties in
>> ./../conf/services.properties
>>
>> INFO  - Including auto-located properties in ./../conf/ldap.properties
>>
>> Enabling idp.authn.X509...
>>
>>         edit-webapp/x509-prompt.jsp created
>>
>> [OK]
>>
>>
>> Customize edit-webapp/x509-prompt.jsp and rebuild war to deploy.
>>
>
> So far, I haven't added the TrustEngine as shown on that page because it
> sounds like that is optional(?).
>
> Also, this page:
>
>
> https://shibboleth.atlassian.net/wiki/spaces/IDP5/pages/3199500577/Installation#Rebuilding-the-WAR-file
>
> Installing plugins automatically performs this step, but should you need
>> to rebuild the WAR file yourself, you can run the build command line
>> utility (*bin/build.sh* or *bin\build.bat*) from the installation
>> directory(idp.home).
>>
>
> so I haven't rebuilt the WAR (yet).
>
> I rebooted the IdP machine and did a test request, but the IdP seems to
> behaving exactly like before I performed those steps.
>
> Do I have to rebuild the WAR file maybe?
>
> Thanks,
> Jim
>
>
>
> <https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=webmail>
> Virus-free.www.avast.com
> <https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=webmail>
> <#m_250734351106095585_DAB4FAD8-2DD7-40BB-A1B8-4E2AA1F9FDF2>
> --
> For Consortium Member technical support, see
> https://shibboleth.atlassian.net/wiki/x/ZYEpPw
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20250522/a8cf5530/attachment.htm>


More information about the users mailing list