<html><head><meta http-equiv="Content-Type" content="text/html charset=iso-8859-1"><base href="x-msg://239/"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; ">Jayashree,<div><br></div><div>Shibboleth will work fine with the SSL termination at the load balancer. &nbsp;You just need to configure the web environment in which the SP runs so that it thinks is the load balancer. &nbsp;You may find this link helpful:</div><div><br></div><div><a href="https://wiki.shibboleth.net/confluence/display/SHIB2/SPReverseProxy">https://wiki.shibboleth.net/confluence/display/SHIB2/SPReverseProxy</a></div><div><br></div><div>Thanks,</div><div>Nate.</div><div><br></div><div><div><div>On 8 Oct 2012, at 17:54, Jayashree Ravi &lt;<a href="mailto:jravi123@hotmail.com">jravi123@hotmail.com</a>&gt; wrote:</div><br class="Apple-interchange-newline"><blockquote type="cite"><div class="hmmessage" style="font-size: 12pt; font-family: Calibri; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; "><div dir="ltr"><div style="margin: 0px; padding: 0px; ">Thanks Scott, &nbsp;We fixed the attribute-map and then we started getting the values. &nbsp;However our operations team has the following to say &nbsp;about SSL:<o:p></o:p></div><div style="margin: 0px; padding: 0px; "><o:p>&nbsp;</o:p></div><div style="margin: 0px; padding: 0px; ">"As a standard for all encrypted web connections SSL certificates are terminated at the F5 load balancer, which make cert management easier for large environments. Please check with Shibboleth developers/support if its possible to patch shibboleth to allow for such a setup to work, this will allow for us to continue to terminate certs on the F5, or is this not an option."<o:p></o:p></div><div style="margin: 0px; padding: 0px; "><o:p>&nbsp;</o:p></div><div style="margin: 0px; padding: 0px; ">Please let us know your thoughts.&nbsp;<o:p></o:p></div><div style="margin: 0px; padding: 0px; "><o:p>&nbsp;</o:p></div><div style="margin: 0px; padding: 0px; ">Thanks again!<o:p></o:p></div><div style="margin: 0px; padding: 0px; ">Jayashree<o:p></o:p></div><div style="margin: 0px; padding: 0px; "><o:p>&nbsp;</o:p></div><br><div><div id="SkyDrivePlaceholder"></div><hr id="stopSpelling">From:<span class="Apple-converted-space">&nbsp;</span><a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a><br>To:<span class="Apple-converted-space">&nbsp;</span><a href="mailto:users@shibboleth.net">users@shibboleth.net</a><br>CC:<span class="Apple-converted-space">&nbsp;</span><a href="mailto:users@shibboleth.net">users@shibboleth.net</a><br>Subject: Re: Adding SAML2 ACS points does not seem to map attributes from        SAML2 IDP<br>Date: Tue, 2 Oct 2012 03:19:11 +0000<br><br><div>On Oct 1, 2012, at 3:47 PM, "Jayashree Ravi" &lt;<a href="mailto:jravi123@hotmail.com">jravi123@hotmail.com</a>&gt; wrote:</div><div><br></div><blockquote><div dir="ltr">2. We also have not enabled SSL between our &nbsp;loadbalancer and Apache/Shibboleth &nbsp;and we do have warning messages in shibd_warn.log&nbsp;</div></blockquote><div><br></div>You are using SSL with the client, so there is no reason to use settings permitting http client access. The warnings are accurate and should be listened to if you allow only https access to your site.&nbsp;<br><div><br></div><div>-- Scott</div><br>-- To unsubscribe from this list send an email to<span class="Apple-converted-space">&nbsp;</span><a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a></div></div>--<br>To unsubscribe from this list send an email to<span class="Apple-converted-space">&nbsp;</span><a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a></div></blockquote></div><br></div></body></html>