Hi Tim,<div><br></div><div>     The AttributeQuery end point is there to allow service providers query IdPs for users attributes. The port is protected so only SPs can access. The SP holds the PKI key which is verified by the IdP before any access is allowed using the SP certificate that is published in the metadata. On the IdP side the SSL is done by a certificate that is also published in the metadata. So if you attempt to do a wget on the URL below you will most likely get refused access because you don&#39;t have the right keys or certificates.</div>
<div><br></div><div>Thanks,</div><div>Terry.<br><br><div class="gmail_quote">On Mon, Oct 22, 2012 at 11:30 AM, Tim O&#39;Connor <span dir="ltr">&lt;<a href="mailto:tim.oconnor@rmit.edu.au" target="_blank">tim.oconnor@rmit.edu.au</a>&gt;</span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div>I have a question about the use of port 8443.  What SHOULD happen when going to the url:</div><div><br></div><div>
<span style="color:windowtext;font-size:11pt;font-family:Calibri,sans-serif"><a href="https://sso-shibboleth-test.its.rmit.edu.au:8443/idp/profile/SAML2/SOAP/AttributeQuery" style="color:rgb(17,85,204);font-family:Verdana,sans-serif;font-size:13px" target="_blank">https://sso-shibboleth-test.its.rmit.edu.au:8443/idp/profile/SAML2/SOAP/AttributeQuery</a></span></div>

<div><br></div><div>I am getting a &#39;connection refused&#39; message.</div><div><br></div><div>We sit behind an f5 which does SSL off loading.  We did get port 8443 excluded from the F5 config, so it is meant to go straight through unaltered.  In my apache config I have an entry for 8443:</div>

<div><br></div><div><div><font face="courier new, monospace">&lt;VirtualHost _default_:8443&gt;</font></div><div><font face="courier new, monospace"><br></font></div><div><font face="courier new, monospace">ServerName <a href="http://sso-shibboleth-test.its.rmit.edu.au:8443" target="_blank">sso-shibboleth-test.its.rmit.edu.au:8443</a></font></div>

<div><font face="courier new, monospace">SSLEngine on</font></div><div><font face="courier new, monospace">SSLProtocol all -SSLv2</font></div><div><font face="courier new, monospace">SSLCipherSuite ALL:!ADH:!EXPORT:!SSLv2:RC4+RSA:+HIGH:+MEDIUM:+LOW</font></div>

<div><font face="courier new, monospace"><br></font></div><div><font face="courier new, monospace">SSLCertificateFile /software/shibboleth/cert/shibboleth-test.crt</font></div><div><font face="courier new, monospace">SSLCertificateKeyFile /software/shibboleth/cert/shibboleth-test.key</font></div>

<div><font face="courier new, monospace"><br></font></div><div><font face="courier new, monospace">SSLVerifyClient optional_no_ca</font></div><div><font face="courier new, monospace">SSLVerifyDepth  10</font></div><div><font face="courier new, monospace"><br>

</font></div><div><font face="courier new, monospace">SSLOptions -StdEnvVars +ExportCertData</font></div><div><font face="courier new, monospace"><br></font></div><div><font face="courier new, monospace">SetEnvIf User-Agent &quot;.*MSIE.*&quot; \</font></div>

<div><font face="courier new, monospace">nokeepalive ssl-unclean-shutdown \</font></div><div><font face="courier new, monospace">downgrade-1.0 force-response-1.0</font></div><div><font face="courier new, monospace"><br></font></div>

<div><font face="courier new, monospace">&lt;IfModule mod_proxy_ajp.c&gt;</font></div><div><font face="courier new, monospace">        ProxyRequests Off</font></div><div><font face="courier new, monospace"><br></font></div>

<div><font face="courier new, monospace">        &lt;Proxy ajp://localhost:8009&gt;</font></div><div><font face="courier new, monospace">                Allow from all</font></div><div><font face="courier new, monospace">        &lt;/Proxy&gt;</font></div>

<div><font face="courier new, monospace"><br></font></div><div><font face="courier new, monospace">        ProxyPass /idp ajp://localhost:8009/idp retry=5</font></div><div><font face="courier new, monospace">&lt;/IfModule&gt;</font></div>

<div><font face="courier new, monospace"><br></font></div><div><font face="courier new, monospace">&lt;/VirtualHost&gt;</font></div></div><div><br></div><div>What I am not sure about is the proxypass settings above, and how that interacts with tomcat exactly...</div>

<div><br></div>
<br>--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br></blockquote></div><br><br clear="all"><div><br></div>-- <br><b><span style="font-size:9pt;font-family:Arial,sans-serif;color:rgb(227,108,10)">Terry Smith</span></b><font style="font-family:verdana,sans-serif" size="1"><font style="font-family:georgia,serif" size="1"> </font><span style="color:rgb(102,102,102)"><font style="font-family:georgia,serif" size="1">| Technical Manager | Australian Access Federation Inc</font></span></font><div>
<b><span style="font-size:8.5pt;font-family:Arial,sans-serif;color:gray">Tel:</span></b> <font size="1"><span style="color:rgb(102,102,102);font-family:verdana,sans-serif"> +61 7 3138 2424 |</span></font> <b><span style="font-size:8.5pt;font-family:Arial,sans-serif;color:gray">Mob:</span></b> <font size="1"><span style="color:rgb(102,102,102);font-family:verdana,sans-serif"> 0414 692 424</span></font></div>
<div><b><span style="font-size:8.5pt;font-family:Arial,sans-serif;color:gray">Email</span></b><font size="1"><span style="color:rgb(102,102,102);font-family:verdana,sans-serif"> </span></font><span style="font-family:Arial,sans-serif;font-size:11px;color:rgb(54,95,145)"><a href="http://twitter.com/ausaccessfed" style="font-family:Arial,sans-serif;font-size:11px;color:rgb(17,85,204)" target="_blank">t.smith@aaf.edu.au</a></span><font size="1"><span style="color:rgb(102,102,102);font-family:verdana,sans-serif"> | </span></font><b><span style="font-size:8.5pt;font-family:Arial,sans-serif;color:gray">Web:</span></b><span style="color:rgb(102,102,102);font-family:verdana,sans-serif;font-size:x-small"> </span><span style="font-family:Arial,sans-serif;font-size:11px;color:rgb(54,95,145)"><a href="http://twitter.com/ausaccessfed" style="color:rgb(17,85,204)" target="_blank">http://www.aaf.edu.au</a></span> <b><span style="font-size:8.5pt;font-family:Arial,sans-serif;color:gray">| Support: </span></b><span style="font-family:Arial,sans-serif;font-size:11px;color:rgb(54,95,145)"><a href="http://twitter.com/ausaccessfed" style="color:rgb(17,85,204)" target="_blank">http://supprt.aaf.edu.au</a></span></div>
<div><b><span style="font-size:8.5pt;font-family:Arial,sans-serif;color:gray">Twitter:</span></b><span style="font-size:8.5pt;font-family:Arial,sans-serif;color:gray"> </span><span style="font-size:8.5pt;font-family:Arial,sans-serif;color:rgb(54,95,145)"><a href="http://twitter.com/ausaccessfed" style="color:rgb(17,85,204)" target="_blank"><span style="color:rgb(54,95,145)">http://twitter.com/ausaccessfed</span></a> </span><b><span style="font-size:8.5pt;font-family:Arial,sans-serif;color:gray">Facebook: </span></b><span style="font-size:8.5pt;font-family:Arial,sans-serif;color:rgb(54,95,145)"><a href="http://facebook.com/ausaccessfed" style="color:rgb(17,85,204)" target="_blank">http://facebook.com/ausaccessfed</a></span></div>
<div><b><span lang="EN-US" style="font-size:8pt;font-family:Arial,sans-serif;color:gray">Mail: PO Box 9432 | Deakin  ACT  2600 | Australia</span></b></div><div><br><img src="http://www.aaf.edu.au/graphics/signature.gif"><br>
</div><br>
</div>