<html><head></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; "><blockquote type="cite"><pre style="orphans: 2; text-align: -webkit-auto; text-indent: 0px; widows: 2; background-color: rgb(255, 255, 255); position: static; -webkit-text-stroke-width: 0px; -webkit-text-size-adjust: auto; word-spacing: 0px; text-transform: none; line-height: normal; letter-spacing: normal; font-weight: normal; font-variant: normal; font-style: normal; color: rgb(0, 0, 0); z-index: auto; ">On Dec 13, 2011, at 6:04 PM, "Matthew Dunham" &lt;<a href="http://shibboleth.net/mailman/listinfo/users">matthew.dunham at oist.ucsb.edu</a>&gt; wrote:
<i> 
</i><i>I'm running a recent (1.4.29 lighttpd), on which the noted patches install cleanly and the config looks like what's been documented. The shib responder does seem to work as advertised, but I can't get the authorizer to seemingly do any authorization. Every attempt to GET a url behind the authorizer returns a 200 success, despite the debug log showing lighttpd handing the request off to the authorizer socket.
</i>
What does the native.log show on DEBUG?

</pre></blockquote><div><div>Nothing exceptional (to my eyes):</div><div><br></div><div><blockquote type="cite"><div>2011-12-14 13:35:39 DEBUG Shibboleth.FastCGI FastCGI shibauthorizer: mapped <a href="https://.ucsb.edu/shibboleth-sp/test.html">https://.ucsb.edu/shibboleth-sp/test.html</a> to default</div><div>2011-12-14 13:35:39 DEBUG Shibboleth.FastCGI FastCGI shibauthorizer: shib: doAuthentication handled the request</div></blockquote></div></div><div><br></div><div>This is a fresh-out-of-the-box 2.4.3 build with the only changes from stock config being a replacement of shibboleth2.xml from testshib and cranking the logs up to DEBUG.</div><div><br></div><div>
<div>--&nbsp;<br>|||||| &nbsp;Matthew E. Dunham<br>|||| &nbsp;Office of Information Systems &amp; Technology<br>|||||| &nbsp;UC Santa Barbara<br>||||||||| 805 451 5814</div>
</div>
<br></body></html>