<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40"><head><meta http-equiv=Content-Type content="text/html; charset=us-ascii"><meta name=Generator content="Microsoft Word 14 (filtered medium)"><style><!--
/* Font Definitions */
@font-face
        {font-family:Wingdings;
        panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
        {font-family:Wingdings;
        panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif";}
h1
        {mso-style-priority:9;
        mso-style-link:"Heading 1 Char";
        mso-margin-top-alt:auto;
        margin-right:0in;
        mso-margin-bottom-alt:auto;
        margin-left:0in;
        font-size:24.0pt;
        font-family:"Times New Roman","serif";}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph
        {mso-style-priority:34;
        margin-top:0in;
        margin-right:0in;
        margin-bottom:0in;
        margin-left:.5in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif";}
span.EmailStyle17
        {mso-style-type:personal-compose;
        font-family:"Calibri","sans-serif";
        color:windowtext;}
span.Heading1Char
        {mso-style-name:"Heading 1 Char";
        mso-style-priority:9;
        mso-style-link:"Heading 1";
        font-family:"Times New Roman","serif";
        font-weight:bold;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-family:"Calibri","sans-serif";}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
/* List Definitions */
@list l0
        {mso-list-id:636910446;
        mso-list-type:hybrid;
        mso-list-template-ids:-379690170 681715212 67698691 67698693 67698689 67698691 67698693 67698689 67698691 67698693;}
@list l0:level1
        {mso-level-start-at:0;
        mso-level-number-format:bullet;
        mso-level-text:-;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;
        font-family:"Calibri","sans-serif";
        mso-fareast-font-family:Calibri;
        mso-bidi-font-family:"Times New Roman";}
@list l0:level2
        {mso-level-number-format:bullet;
        mso-level-text:o;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;
        font-family:"Courier New";}
@list l0:level3
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;
        font-family:Wingdings;}
@list l0:level4
        {mso-level-number-format:bullet;
        mso-level-text:\F0B7;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;
        font-family:Symbol;}
@list l0:level5
        {mso-level-number-format:bullet;
        mso-level-text:o;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;
        font-family:"Courier New";}
@list l0:level6
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;
        font-family:Wingdings;}
@list l0:level7
        {mso-level-number-format:bullet;
        mso-level-text:\F0B7;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;
        font-family:Symbol;}
@list l0:level8
        {mso-level-number-format:bullet;
        mso-level-text:o;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;
        font-family:"Courier New";}
@list l0:level9
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;
        font-family:Wingdings;}
ol
        {margin-bottom:0in;}
ul
        {margin-bottom:0in;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]--></head><body lang=EN-US link=blue vlink=purple><div class=WordSection1><p class=MsoNormal>Hello group.<o:p></o:p></p><p class=MsoNormal>I’m new to shibboleth and saml in general and am trying to figure out many things at once.<o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal>Mostly, my goal is to configure an existing asp.net/mvc application as an SP that uses an existing IP for authentication.<o:p></o:p></p><p class=MsoNormal><br>Conceptually, I think I get it. <o:p></o:p></p><p class=MsoListParagraph style='text-indent:-.25in;mso-list:l0 level1 lfo1'><![if !supportLists]><span style='mso-list:Ignore'>-<span style='font:7.0pt "Times New Roman"'> </span></span><![endif]>Install the shibboleth SP service and isapi filter on my web server<o:p></o:p></p><p class=MsoListParagraph style='text-indent:-.25in;mso-list:l0 level1 lfo1'><![if !supportLists]><span style='mso-list:Ignore'>-<span style='font:7.0pt "Times New Roman"'> </span></span><![endif]>Configure shibboleth to use some specified IP<o:p></o:p></p><p class=MsoListParagraph style='text-indent:-.25in;mso-list:l0 level1 lfo1'><![if !supportLists]><span style='mso-list:Ignore'>-<span style='font:7.0pt "Times New Roman"'> </span></span><![endif]>When requests make it to my application, examine some headers to determine the user id set during authentication<o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal>Problem is, I can’t get off the ground, so I’m a little vague on what step 3 there would look like exactly, but that should be the easy part once I get shibboleth configured.<o:p></o:p></p><p class=MsoNormal>I want to use a test IP at <a href="http://testshib.org/">http://testshib.org/</a> for my development.<o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal>My development box is windows 7 pro, IIS 7. <o:p></o:p></p><p class=MsoNormal>On that box, I was able to install shibboleth 2.5 and after a little mucking around to get the 32/64 bit stuff straight, I can send a request to my sever such as <o:p></o:p></p><p class=MsoNormal style='text-indent:.5in'><a href="http://myserver/Shibboleth.sso/Metadata">http://myserver/Shibboleth.sso/Metadata</a> <o:p></o:p></p><p class=MsoNormal>and a nice bunch of XML goo spits out.<o:p></o:p></p><p class=MsoNormal>Problem is, that machine is not publicly visible, so I think it doesn’t do me much good as far as trying to register that metadata with the test IP. <o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal>So, I move to a publicly visible test server that we have set up for this. This machine is Windows Server 2008 R2 with IIS 7.5, and certificates for SSL.<o:p></o:p></p><p class=MsoNormal>The IIS configuration has one Web Site, ID=1 with bindings for both http and https, but not requiring https.<o:p></o:p></p><p class=MsoNormal>Again, installed shibboleth and have the appropriate looking handlers present.<o:p></o:p></p><p class=MsoNormal>Here, when I do <a href="http://shibtest.mycompany.com/Shibboleth.sso/Metadata">http://shibtest.mycompany.com/Shibboleth.sso/Metadata</a> (or if on that box just the computer name)<o:p></o:p></p><p class=MsoNormal>I get the error page with a message:<o:p></o:p></p><p class=MsoNormal style='text-indent:.5in'><i>Shibboleth Error<o:p></o:p></i></p><p class=MsoNormal style='text-indent:.5in'><i>ISAPI extension can only be invoked to process Shibboleth protocol requests.Make sure the mapped file extension doesn't match actual content.<o:p></o:p></i></p><p class=MsoNormal><br>I am sure that the isapi filter is up and running and processing requests. <o:p></o:p></p><p class=MsoNormal>I cranked up the native.logging to debug, and I see this for an incoming request:<o:p></o:p></p><p class=MsoNormal><i>2013-06-01 11:11:58 DEBUG Shibboleth.ISAPI [3968] isapi_shib: mapped http:// shibtest.mycompany.com /Shibboleth.sso/Metadata to default<o:p></o:p></i></p><p class=MsoNormal><i>2013-06-01 11:11:58 DEBUG Shibboleth.ISAPI [3968] isapi_shib_extension: mapped http:// shibtest.mycompany.com /Shibboleth.sso/Metadata to default<o:p></o:p></i></p><p class=MsoNormal><i><o:p> </o:p></i></p><p class=MsoNormal>Whereas, on my windows 7 box, where the metadata is retrieved, I get similar mapping entries, as well as some additional entries indicating that the message is being sent to the shibd service:<o:p></o:p></p><p class=MsoNormal><i>2013-06-01 10:43:27 DEBUG Shibboleth.ISAPI [3344] isapi_shib: mapped http://rreynolds/Shibboleth.sso/Metadata to default<o:p></o:p></i></p><p class=MsoNormal><i>2013-06-01 10:43:27 DEBUG Shibboleth.ISAPI [3344] isapi_shib_extension: mapped http://rreynolds/Shibboleth.sso/Metadata to default<o:p></o:p></i></p><p class=MsoNormal><i>2013-06-01 10:43:27 DEBUG Shibboleth.Listener [3344] isapi_shib_extension: sending message (default/Metadata)<o:p></o:p></i></p><p class=MsoNormal><i>2013-06-01 10:43:27 DEBUG Shibboleth.Listener [3344] isapi_shib_extension: trying to connect to listener<o:p></o:p></i></p><p class=MsoNormal><i>2013-06-01 10:43:27 DEBUG Shibboleth.Listener [3344] isapi_shib_extension: socket (880) connected successfully<o:p></o:p></i></p><p class=MsoNormal><i>2013-06-01 10:43:27 DEBUG Shibboleth.Listener [3344] isapi_shib_extension: send completed, reading response message<o:p></o:p></i></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal>Also, note that if I stop the shibd service, it makes no difference. By that I conclude that the ISAPI filter is not recognizing the request as being something that it wants to handle. <o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal>I have tried configuring my shibboleth2.xml file’s host name entries (/ISAPI/site/@name, and RequestMap/Host/@name, as both my computer name (as it is in the working windows 7 dev machine case) and with the official DNS name. Makes no difference.<o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal>I’m about out of ideas, and sure would appreciate if anyone can clue me in on what to try next.<o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal>Also, an unrelated question - is Shibboleth supported, or can it be manually configured, for Windows Server 2012 and IIS 8? It doesn’t appear to be listed as such, and there are no ISAPI Filters in IIS8, so my assumption is that it is not possible. Is that correct?<o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal>Thanks <o:p></o:p></p><p class=MsoNormal>Roger Reynolds.<o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal><o:p> </o:p></p></div></body></html>