<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40"><head><meta http-equiv=Content-Type content="text/html; charset=us-ascii"><meta name=Generator content="Microsoft Word 14 (filtered medium)"><style><!--
/* Font Definitions */
@font-face
        {font-family:Wingdings;
        panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
        {font-family:Wingdings;
        panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif";}
h1
        {mso-style-priority:9;
        mso-style-link:"Heading 1 Char";
        mso-margin-top-alt:auto;
        margin-right:0in;
        mso-margin-bottom-alt:auto;
        margin-left:0in;
        font-size:24.0pt;
        font-family:"Times New Roman","serif";}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph
        {mso-style-priority:34;
        margin-top:0in;
        margin-right:0in;
        margin-bottom:0in;
        margin-left:.5in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif";}
span.EmailStyle17
        {mso-style-type:personal-compose;
        font-family:"Calibri","sans-serif";
        color:windowtext;}
span.Heading1Char
        {mso-style-name:"Heading 1 Char";
        mso-style-priority:9;
        mso-style-link:"Heading 1";
        font-family:"Times New Roman","serif";
        font-weight:bold;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-family:"Calibri","sans-serif";}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
/* List Definitions */
@list l0
        {mso-list-id:636910446;
        mso-list-type:hybrid;
        mso-list-template-ids:-379690170 681715212 67698691 67698693 67698689 67698691 67698693 67698689 67698691 67698693;}
@list l0:level1
        {mso-level-start-at:0;
        mso-level-number-format:bullet;
        mso-level-text:-;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;
        font-family:"Calibri","sans-serif";
        mso-fareast-font-family:Calibri;
        mso-bidi-font-family:"Times New Roman";}
@list l0:level2
        {mso-level-number-format:bullet;
        mso-level-text:o;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;
        font-family:"Courier New";}
@list l0:level3
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;
        font-family:Wingdings;}
@list l0:level4
        {mso-level-number-format:bullet;
        mso-level-text:\F0B7;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;
        font-family:Symbol;}
@list l0:level5
        {mso-level-number-format:bullet;
        mso-level-text:o;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;
        font-family:"Courier New";}
@list l0:level6
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;
        font-family:Wingdings;}
@list l0:level7
        {mso-level-number-format:bullet;
        mso-level-text:\F0B7;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;
        font-family:Symbol;}
@list l0:level8
        {mso-level-number-format:bullet;
        mso-level-text:o;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;
        font-family:"Courier New";}
@list l0:level9
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:none;
        mso-level-number-position:left;
        text-indent:-.25in;
        font-family:Wingdings;}
ol
        {margin-bottom:0in;}
ul
        {margin-bottom:0in;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]--></head><body lang=EN-US link=blue vlink=purple><div class=WordSection1><p class=MsoNormal>Hello group.<o:p></o:p></p><p class=MsoNormal>I&#8217;m new to shibboleth and saml in general and am trying to figure out many things at once.<o:p></o:p></p><p class=MsoNormal><o:p>&nbsp;</o:p></p><p class=MsoNormal>Mostly, my goal is to configure an existing asp.net/mvc application as an SP that uses an existing IP for authentication.<o:p></o:p></p><p class=MsoNormal><br>Conceptually, I think I get it.&nbsp; <o:p></o:p></p><p class=MsoListParagraph style='text-indent:-.25in;mso-list:l0 level1 lfo1'><![if !supportLists]><span style='mso-list:Ignore'>-<span style='font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><![endif]>Install the shibboleth SP service and isapi filter on my web server<o:p></o:p></p><p class=MsoListParagraph style='text-indent:-.25in;mso-list:l0 level1 lfo1'><![if !supportLists]><span style='mso-list:Ignore'>-<span style='font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><![endif]>Configure shibboleth to use some specified IP<o:p></o:p></p><p class=MsoListParagraph style='text-indent:-.25in;mso-list:l0 level1 lfo1'><![if !supportLists]><span style='mso-list:Ignore'>-<span style='font:7.0pt "Times New Roman"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></span><![endif]>When requests make it to my application, examine some headers to determine the user id set during authentication<o:p></o:p></p><p class=MsoNormal><o:p>&nbsp;</o:p></p><p class=MsoNormal>Problem is, I can&#8217;t get off the ground, so I&#8217;m a little vague on what step 3 there would look like exactly, but that should be the easy part once I get shibboleth configured.<o:p></o:p></p><p class=MsoNormal>I want to use a test IP at <a href="http://testshib.org/">http://testshib.org/</a> for my development.<o:p></o:p></p><p class=MsoNormal><o:p>&nbsp;</o:p></p><p class=MsoNormal>My development box is windows&nbsp; 7 pro, IIS 7.&nbsp; &nbsp;<o:p></o:p></p><p class=MsoNormal>On that box, I was able to install shibboleth 2.5 and after a little mucking around to get the 32/64 bit stuff straight, I can send a request to my sever such as <o:p></o:p></p><p class=MsoNormal style='text-indent:.5in'><a href="http://myserver/Shibboleth.sso/Metadata">http://myserver/Shibboleth.sso/Metadata</a> <o:p></o:p></p><p class=MsoNormal>and a nice bunch of XML goo spits out.<o:p></o:p></p><p class=MsoNormal>Problem is, that machine is not publicly visible, so I think it doesn&#8217;t do me much good as far as trying to register that metadata with the test IP. <o:p></o:p></p><p class=MsoNormal><o:p>&nbsp;</o:p></p><p class=MsoNormal>So, I move to a publicly visible test server that we have set up for this.&nbsp; This machine is Windows Server 2008 R2 with IIS 7.5, and certificates for SSL.<o:p></o:p></p><p class=MsoNormal>The IIS configuration has one Web Site, ID=1 with bindings for both http and https, but not requiring https.<o:p></o:p></p><p class=MsoNormal>Again, installed shibboleth and have the appropriate looking handlers present.<o:p></o:p></p><p class=MsoNormal>Here, when I do <a href="http://shibtest.mycompany.com/Shibboleth.sso/Metadata">http://shibtest.mycompany.com/Shibboleth.sso/Metadata</a> &nbsp;&nbsp;&nbsp;(or if on that box just the computer&nbsp; name)<o:p></o:p></p><p class=MsoNormal>I get the error page with a message:<o:p></o:p></p><p class=MsoNormal style='text-indent:.5in'><i>Shibboleth Error<o:p></o:p></i></p><p class=MsoNormal style='text-indent:.5in'><i>ISAPI extension can only be invoked to process Shibboleth protocol requests.Make sure the mapped file extension doesn't match actual content.<o:p></o:p></i></p><p class=MsoNormal><br>I am sure that the isapi filter is up and running and processing requests. <o:p></o:p></p><p class=MsoNormal>I cranked up the native.logging to debug, and I see this for an incoming request:<o:p></o:p></p><p class=MsoNormal><i>2013-06-01 11:11:58 DEBUG Shibboleth.ISAPI [3968] isapi_shib: mapped http:// shibtest.mycompany.com /Shibboleth.sso/Metadata to default<o:p></o:p></i></p><p class=MsoNormal><i>2013-06-01 11:11:58 DEBUG Shibboleth.ISAPI [3968] isapi_shib_extension: mapped http:// shibtest.mycompany.com /Shibboleth.sso/Metadata to default<o:p></o:p></i></p><p class=MsoNormal><i><o:p>&nbsp;</o:p></i></p><p class=MsoNormal>Whereas, on my windows 7 box, where the metadata is retrieved, I get similar mapping entries, as well as some additional entries indicating that the message is being sent to the shibd service:<o:p></o:p></p><p class=MsoNormal><i>2013-06-01 10:43:27 DEBUG Shibboleth.ISAPI [3344] isapi_shib: mapped http://rreynolds/Shibboleth.sso/Metadata to default<o:p></o:p></i></p><p class=MsoNormal><i>2013-06-01 10:43:27 DEBUG Shibboleth.ISAPI [3344] isapi_shib_extension: mapped http://rreynolds/Shibboleth.sso/Metadata to default<o:p></o:p></i></p><p class=MsoNormal><i>2013-06-01 10:43:27 DEBUG Shibboleth.Listener [3344] isapi_shib_extension: sending message (default/Metadata)<o:p></o:p></i></p><p class=MsoNormal><i>2013-06-01 10:43:27 DEBUG Shibboleth.Listener [3344] isapi_shib_extension: trying to connect to listener<o:p></o:p></i></p><p class=MsoNormal><i>2013-06-01 10:43:27 DEBUG Shibboleth.Listener [3344] isapi_shib_extension: socket (880) connected successfully<o:p></o:p></i></p><p class=MsoNormal><i>2013-06-01 10:43:27 DEBUG Shibboleth.Listener [3344] isapi_shib_extension: send completed, reading response message<o:p></o:p></i></p><p class=MsoNormal><o:p>&nbsp;</o:p></p><p class=MsoNormal>Also, note that if I stop the shibd service, it makes no difference.&nbsp; By that I conclude that the ISAPI filter is not recognizing the request as being something that it wants to handle. <o:p></o:p></p><p class=MsoNormal><o:p>&nbsp;</o:p></p><p class=MsoNormal>I have tried configuring my shibboleth2.xml file&#8217;s host name entries (/ISAPI/site/@name, and RequestMap/Host/@name, as both my computer name (as it is in the working windows 7 dev machine case)&nbsp; and with the official DNS name. Makes no difference.<o:p></o:p></p><p class=MsoNormal><o:p>&nbsp;</o:p></p><p class=MsoNormal>I&#8217;m about out of ideas, and sure would appreciate if anyone can clue me in on what to try next.<o:p></o:p></p><p class=MsoNormal><o:p>&nbsp;</o:p></p><p class=MsoNormal>Also, an unrelated question -&nbsp;&nbsp; is Shibboleth supported, or can it be manually configured, for Windows Server 2012 and IIS 8?&nbsp; It doesn&#8217;t appear to be listed as such, and there are no ISAPI Filters in IIS8, so my assumption is that it is not possible.&nbsp; Is that correct?<o:p></o:p></p><p class=MsoNormal><o:p>&nbsp;</o:p></p><p class=MsoNormal><o:p>&nbsp;</o:p></p><p class=MsoNormal>Thanks <o:p></o:p></p><p class=MsoNormal>Roger Reynolds.<o:p></o:p></p><p class=MsoNormal><o:p>&nbsp;</o:p></p><p class=MsoNormal><o:p>&nbsp;</o:p></p></div></body></html>