<html>
<head>
<meta content="text/html; charset=ISO-8859-1"
http-equiv="Content-Type">
</head>
<body bgcolor="#FFFFFF" text="#000000">
<div class="moz-cite-prefix">On 10/1/13 11:55 AM, Caskey, Paul
wrote:<br>
</div>
<blockquote
cite="mid:788B43FEFE8CD84A8BCCD3B5A3336EAF2A1541BD@EX10b.utsystem.local"
type="cite">
<meta http-equiv="Content-Type" content="text/html;
charset=ISO-8859-1">
<meta name="Generator" content="Microsoft Word 14 (filtered
medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Tahoma;
        panose-1:2 11 6 4 3 5 4 4 2 4;}
@font-face
        {font-family:Consolas;
        panose-1:2 11 6 9 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:12.0pt;
        font-family:"Times New Roman","serif";
        color:black;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
code
        {mso-style-priority:99;
        font-family:"Courier New";}
pre
        {mso-style-priority:99;
        mso-style-link:"HTML Preformatted Char";
        margin:0in;
        margin-bottom:.0001pt;
        font-size:10.0pt;
        font-family:"Courier New";
        color:black;}
span.HTMLPreformattedChar
        {mso-style-name:"HTML Preformatted Char";
        mso-style-priority:99;
        mso-style-link:"HTML Preformatted";
        font-family:Consolas;
        color:black;}
span.EmailStyle20
        {mso-style-type:personal-reply;
        font-family:"Calibri","sans-serif";
        color:#1F497D;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
<div class="WordSection1">
<p class="MsoNormal"><span
style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D">Not
sure why the wiki omits that, but here’s what you need in
tomcat’s server.xml for port 443 (you can substitute your
own commercial cert for idp.jks):<o:p></o:p></span></p>
<p class="MsoNormal"><span
style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal" style="line-height:13.0pt"><span
style="font-size:10.0pt;font-family:"Courier
New";color:#333333"><Connector</span><span
style="font-size:10.0pt;font-family:"Arial","sans-serif";color:#333333"><o:p></o:p></span></p>
<p class="MsoNormal" style="line-height:13.0pt"><span
style="font-size:10.0pt;font-family:"Courier
New";color:#333333">port="443"</span><span
style="font-size:10.0pt;font-family:"Arial","sans-serif";color:#333333"><o:p></o:p></span></p>
<p class="MsoNormal" style="line-height:13.0pt"><span
style="font-size:10.0pt;font-family:"Courier
New";color:#333333">protocol="HTTP/1.1"</span><span
style="font-size:10.0pt;font-family:"Arial","sans-serif";color:#333333"><o:p></o:p></span></p>
<p class="MsoNormal" style="line-height:13.0pt"><span
style="font-size:10.0pt;font-family:"Courier
New";color:#333333">SSLEnabled="true"</span><span
style="font-size:10.0pt;font-family:"Arial","sans-serif";color:#333333"><o:p></o:p></span></p>
<p class="MsoNormal" style="line-height:13.0pt"><span
style="font-size:10.0pt;font-family:"Courier
New";color:#333333">maxThreads="150"</span><span
style="font-size:10.0pt;font-family:"Arial","sans-serif";color:#333333"><o:p></o:p></span></p>
<p class="MsoNormal" style="line-height:13.0pt"><span
style="font-size:10.0pt;font-family:"Courier
New";color:#333333">scheme="https"</span><span
style="font-size:10.0pt;font-family:"Arial","sans-serif";color:#333333"><o:p></o:p></span></p>
<p class="MsoNormal" style="line-height:13.0pt"><span
style="font-size:10.0pt;font-family:"Courier
New";color:#333333">secure="true"</span><span
style="font-size:10.0pt;font-family:"Arial","sans-serif";color:#333333"><o:p></o:p></span></p>
<p class="MsoNormal" style="line-height:13.0pt"><span
style="font-size:10.0pt;font-family:"Courier
New";color:#333333">clientAuth="false"</span><span
style="font-size:10.0pt;font-family:"Arial","sans-serif";color:#333333"><o:p></o:p></span></p>
<p class="MsoNormal" style="line-height:13.0pt"><span
style="font-size:10.0pt;font-family:"Courier
New";color:#333333">sslProtocol="TLS"</span><span
style="font-size:10.0pt;font-family:"Arial","sans-serif";color:#333333"><o:p></o:p></span></p>
<p class="MsoNormal" style="line-height:13.0pt"><span
style="font-size:10.0pt;font-family:"Courier
New";color:#333333">keystoreFile="/opt/shibboleth-idp/credentials/idp.jks"
</span><span
style="font-size:10.0pt;font-family:"Arial","sans-serif";color:#333333"><o:p></o:p></span></p>
<p class="MsoNormal" style="line-height:13.0pt"><span
style="font-size:10.0pt;font-family:"Courier
New";color:#333333">keystorePass="YourSecretPassword"</span><span
style="font-size:10.0pt;font-family:"Arial","sans-serif";color:#333333">
</span><span style="font-size:10.0pt;font-family:"Courier
New";color:#333333">/> </span>
<span
style="font-size:10.0pt;font-family:"Arial","sans-serif";color:#333333"><o:p></o:p></span></p>
<p class="MsoNormal"><span
style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span
style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span
style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span
style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"><o:p> </o:p></span></p>
<div style="border:none;border-left:solid blue 1.5pt;padding:0in
0in 0in 4.0pt">
<div>
<div style="border:none;border-top:solid #B5C4DF
1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span
style="font-size:10.0pt;font-family:"Tahoma","sans-serif";color:windowtext">From:</span></b><span
style="font-size:10.0pt;font-family:"Tahoma","sans-serif";color:windowtext">
<a class="moz-txt-link-abbreviated" href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a>
[<a class="moz-txt-link-freetext" href="mailto:users-bounces@shibboleth.net">mailto:users-bounces@shibboleth.net</a>]
<b>On Behalf Of </b>Joaquin Menchaca<br>
<b>Sent:</b> Tuesday, October 01, 2013 12:51 PM<br>
<b>To:</b> <a class="moz-txt-link-abbreviated" href="mailto:users@shibboleth.net">users@shibboleth.net</a><br>
<b>Subject:</b> Re: Shibboleth IdP
(Tomcat6/OpenJDK1.6) Fresh Install Issues<o:p></o:p></span></p>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<div>
<p class="MsoNormal">On 10/1/13 10:33 AM, Kevin P. Foote
wrote:<o:p></o:p></p>
</div>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<pre>You will not see the endpoints or locations you see on the frontside communication<o:p></o:p></pre>
<pre>port generally (443) or if your offloading via apache or balancer <o:p></o:p></pre>
<pre>your normal www port..<o:p></o:p></pre>
</blockquote>
<p class="MsoNormal" style="margin-bottom:12.0pt">I was
following the process in in the wiki (1), that says to test
if the IdP is properly installed by using the URL:<br>
<br>
<code><span style="font-size:10.0pt"><a
moz-do-not-send="true"
href="https://HOSTNAME/idp/profile/Status">https://HOSTNAME/idp/profile/Status</a></span></code><span
style="font-size:10.0pt;font-family:"Courier
New""><br>
<br>
<code>I followed the instructions using the Tomcat
Container (2). The instructions doesn't mention
configured the connectors others than port 8443 for
Supporting SOAP Endpoints. Is there a connector I
should add for 443? Do I need to install a certificate
in the keystore? </code><br>
<br>
<code>I am relatively new to Tomcat configurations. </code><br>
</span><br>
<br>
1 - <a moz-do-not-send="true"
href="https://wiki.shibboleth.net/confluence/display/SHIB2/IdPInstall">https://wiki.shibboleth.net/confluence/display/SHIB2/IdPInstall</a><br>
2 - <a moz-do-not-send="true"
href="https://wiki.shibboleth.net/confluence/display/SHIB2/IdPApacheTomcatPrepare">https://wiki.shibboleth.net/confluence/display/SHIB2/IdPApacheTomcatPrepare</a><br>
<br>
<o:p></o:p></p>
</div>
</div>
<br>
<fieldset class="mimeAttachmentHeader"></fieldset>
<br>
<pre wrap="">--
To unsubscribe from this list send an email to <a class="moz-txt-link-abbreviated" href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a></pre>
</blockquote>
Hello.<br>
<br>
Thank you. I think I found a solution path: have load balancer take
incoming 443 and send it to 9443, which I have a connector
configured for that (from the snippet you sent me).<br>
<br>
To have a local server listen on 443 gets complicated as I have just
learned, as you have to either have a service run as root to
initially listen on 443, or configure SELinux to permit a particular
process to listen on 443. <br>
<br>
As I installed tomcat from RPMs, I would either have change its
config (re-chown dirs, etc.) or uninstall and re-install from
source, or I would have to put an Apache httpd front end server,
which opens a whole can of worms to configure this, e.g.
reconfiguring 8009 connector in tomcat.<br>
<br>
- Joaquin Menchaca<br>
</body>
</html>