<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 12 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
span.EmailStyle17
        {mso-style-type:personal-compose;
        font-family:"Calibri","sans-serif";
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal">OK. So I installed Tomcat 6 and got the SSLImplementation working. That took care of the problem.<o:p></o:p></p>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal">However, I am still getting the Firefox Warning (Although this page is encrypted, the information you have entered is to be sent over an unencrypted connection and could easily be read by a third party.<o:p></o:p></p>
<p class="MsoNormal">Are you sure you want to continue sending this information?)after I am authenticated via the log in page Shibboleth brings up and am returned to the protected source. So I&nbsp; don&#8217;t know how to fix this. Again the loadbalancer is terminating
 SSL on the LB but 80 and 443 ports are open on the SP side. LB has 8443 port open on the IDP side. I have the metadata endpoints (except soap and queries which are https and 8443) as https and :443.<o:p></o:p></p>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal">The only error message that I am getting is in the SP apache logs. It points to the Virtual host. It says:<o:p></o:p></p>
<p class="MsoNormal">[Fri Aug 12 15:24:37 2011] [error] [client (idp address)] Invalid method in request \x16\x03\x01<o:p></o:p></p>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal">So I am back to the Virtual Host as most likely the issue here that this forum helped me set up. It is pasted below.
<o:p></o:p></p>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal">Listen 443<o:p></o:p></p>
<p class="MsoNormal">NameVirtualHost *:80<o:p></o:p></p>
<p class="MsoNormal">&lt;VirtualHost *:80&gt;<o:p></o:p></p>
<p class="MsoNormal">ServerName https://(my domain):443<o:p></o:p></p>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal">&lt;Location /&gt;<o:p></o:p></p>
<p class="MsoNormal">AuthType shibboleth<o:p></o:p></p>
<p class="MsoNormal">require shibboleth<o:p></o:p></p>
<p class="MsoNormal">&lt;/Location&gt;<o:p></o:p></p>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal">&lt;Location /Shibboleth.sso&gt;<o:p></o:p></p>
<p class="MsoNormal">AuthType shibboleth<o:p></o:p></p>
<p class="MsoNormal">require shibboleth<o:p></o:p></p>
<p class="MsoNormal">&lt;/Location&gt;<o:p></o:p></p>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal">&lt;Location /shibboleth-sp&gt;<o:p></o:p></p>
<p class="MsoNormal">&nbsp;&nbsp;&nbsp;&nbsp; Allow from all<o:p></o:p></p>
<p class="MsoNormal">&lt;/Location&gt;<o:p></o:p></p>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal">ServerAdmin admin@(mydomain)<o:p></o:p></p>
<p class="MsoNormal">ErrorLog &quot;/usr/local/zend/apache2/logs/error_log&quot;<o:p></o:p></p>
<p class="MsoNormal">TransferLog &quot;/usr/local/zend/apache2/logs/access_log&quot;<o:p></o:p></p>
<p class="MsoNormal">UseCanonicalName On<o:p></o:p></p>
<p class="MsoNormal">SSLEngine on<o:p></o:p></p>
<p class="MsoNormal">SSLCipherSuite (myciphersuite)<o:p></o:p></p>
<p class="MsoNormal">SSLCertificateFile &quot;/usr/local/zend/apache2/conf/extra/(mydomain.crt&quot;<o:p></o:p></p>
<p class="MsoNormal">SSLCertificateKeyFile &quot;/usr/local/zend/apache2/conf/extra/myserver.key&quot;<o:p></o:p></p>
<p class="MsoNormal">SSLCertificateChainFile &quot;/usr/local/zend/apache2/conf/extra/chain.crt&quot;<o:p></o:p></p>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal">Is this because the LB is terminating SSL. So the SSL is broken at that point. But then my SP picks up SSL again with the above Virtual Host? Because once the user lands back on the SPs the browser shows SSl and the certificates.
<o:p></o:p></p>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal"><o:p>&nbsp;</o:p></p>
<p class="MsoNormal">Thanks,<o:p></o:p></p>
<p class="MsoNormal">Tommy<o:p></o:p></p>
</div>
<br>
<hr>
<font face="Arial" color="Black" size="1">This message contains Devin Group confidential information and is intended only for the individual named. If you are not the named addressee you should not disseminate, distribute or copy this e-mail.<br>
Please notify the sender immediately by e-mail if you have received this e-mail in error and delete this e-mail from your system. E-mail transmissions cannot be guaranteed secure, error-free and information could be intercepted, corrupted, lost, destroyed,
 arrive late, incomplete, or contain viruses. The sender therefore does not accept liability for errors or omissions in the contents of this message which may arise as result of transmission. If verification is required please request hard-copy version.<br>
</font>
</body>
</html>