Hey Scott,
<br/><br/><br/>Thank you for you quick reply. That's great to hear that Shibboleth
<br/>IDP can use MySql. I'd looked into it long ago and had written that
<br/>off, thinking it only worked with LDAP+ SQL with a great deal of
<br/>hacking.
<br/>However, the complexity of setting up the Shibboleth IDP had really
<br/>kept me from progressing on it sooner. It's possible I can set it all
<br/>up I think (I've tried at least twice) but the value return in
<br/>exchange, was just not high enough for what we were neeeding right at the
<br/>moment with the time available to work on it. I want to
<br/>eventually use Shibboleth for both SP and IDP now knowing that
<br/>Shibboleth IDP can indeed use MySql. That's really good information.
<br/>Thank you for confirming that!
<br/>First, I want to use simplesaml as the IDP as a learning exercise and
<br/>because it's just... ...well, "simpler" .
<br/><br/>Also, I was also recommended by someone who runs a company managing
<br/>Shibboleth installations to not use Shibboleth IDP when it sounded
<br/>like I could just use simplesaml for my purpose and that I should
<br/>continue with simplesaml since I'm a novice still. So fore now,
<br/>simplesaml it is!
<br/><br/>> Yes, do each one separately and that's it.
<br/>>
<br/>> -- Scott
<br/>>
<br/><br/>This sounds interesting. Indeed! please elaborate... :D
<br/><br/>Oh btw, I did get the SP to talk to TestShib. I can log into TestShib
<br/>after being redirected from the SP, and it comes back with attributes
<br/>that I can use. I now need to put the SP metadata inside the
<br/>simplesaml IDP and the IDP metadata inside the Shibboleth SP; I just
<br/>don't know where to put it (which hosted filed/format?).
<br/>I'm wodering if it's, that the metadata is in the wrong place. I'm
<br/>going from memory here because I'm not at the computers that have the
<br/>Shibboleth SP and simplesaml IDP (links are cached in browser), but I
<br/>think I did something like:
<br/><br/>At the IDP, generated the IDP metadata the Shibboleth SP side would need at:
<br/><a href="http://192.168.23.110/simplesaml/saml2/idp/metadata.php" target="_top" rel="nofollow" link="external">http://192.168.23.110/simplesaml/saml2/idp/metadata.php</a><br/>(got a lot of xml data)
<br/><br/>At the SP, generated the SP medata that the simplesaml IDP would need at:
<br/><a href="http://192.168.23.111/Shibboleth.sso/Metadata" target="_top" rel="nofollow" link="external">http://192.168.23.111/Shibboleth.sso/Metadata</a><br/>(got a download prompt, contains xml metadata for the Shibboleth SP
<br/>including entityID= line)
<br/><br/>Then on the simplesaml IDP side, I used:
<br/><a href="http://192.168.23.110/simplesaml/admin/metadata-converter.php" target="_top" rel="nofollow" link="external">http://192.168.23.110/simplesaml/admin/metadata-converter.php</a><br/>to get the shibboleth SP metadata into a format that simplesaml
<br/>needed. Looks like php code.
<br/><br/>I hunted around the internet and determined that I needed to put that
<br/>converted text into a file on the IDP, but am not sure which one. Also
<br/>I'm not sure where to put the IDP metadata on my Shibboleth SP.
<br/><br/>I think I'm almost there but just need a little help on the last part
<br/>to get over the hump. Can you help?
<br/><br/><br/>Thanks!
<br/><br/><br/><br/>Quoting "Cantor, Scott E. [via Shibboleth]"
<br/><<a href="/user/SendEmail.jtp?type=node&node=7590741&i=0" target="_top" rel="nofollow" link="external">[hidden email]</a>>:
<br/><div class='shrinkable-quote'><br/>>
<br/>>
<br/>> On 10/14/13 2:43 AM, "trey" <<a href="/user/SendEmail.jtp?type=node&node=7590741&i=1" target="_top" rel="nofollow" link="external">[hidden email]</a>> wrote:
<br/>>
<br/>>> I have been trying for over a week to do what you've accomplished but
<br/>>> can't
<br/>>> seem to get the metdata correct (I guess that is the issue). I've looked
<br/>>> on
<br/>>> the internet a lot and have found plenty of simplesaml SP with Shibboleth
<br/>>> IDP documentation.
<br/>>
<br/>> There is nothing substantial you should have to do with a Shibboleth SP
<br/>> here at all. It just works, SSP is perfectly compliant in most respects.
<br/>>
<br/>>> However, Shibboleth IDP is so complex for my needs as
<br/>>> well as it uses LDAP and I prefer to use the mysql connector in simplesaml
<br/>>> for looking up and authenticating users.
<br/>>
<br/>> Shibboleth can use MySQL just fine. It does *not* require LDAP.
<br/>>
<br/>>> Can you, or anyone else, please let me know how you were able to set up
<br/>>> simplesaml for the IDP and Shibboleth for the SP?
<br/>>
<br/>> Yes, do each one separately and that's it.
<br/>>
<br/>> -- Scott
<br/>>
<br/>>
<br/>> --
<br/>> To unsubscribe from this list send an email to
<br/>> <a href="/user/SendEmail.jtp?type=node&node=7590741&i=2" target="_top" rel="nofollow" link="external">[hidden email]</a>
<br/>>
<br/>>
<br/>>
<br/>>
<br/>> _______________________________________________
<br/>> If you reply to this email, your message will be added to the
<br/>> discussion below:
<br/>> <a href="http://shibboleth.1660669.n2.nabble.com/Broke-delete-user-session-tp6203911p7590551.html" target="_top" rel="nofollow" link="external">http://shibboleth.1660669.n2.nabble.com/Broke-delete-user-session-tp6203911p7590551.html</a><br/>>
<br/>> To unsubscribe from Broke - delete user session, visit
<br/>> <a href="" target="_top" rel="nofollow" link="external">
        
        
        
<br/><hr align="left" width="300" />
View this message in context: <a href="http://shibboleth.1660669.n2.nabble.com/Broke-delete-user-session-tp6203911p7590741.html">Re: How to set up simplesaml for the IDP and Shibboleth for the SP Was: Re: Broke - delete user session</a><br/>
Sent from the <a href="http://shibboleth.1660669.n2.nabble.com/Shibboleth-Users-f1660767.html">Shibboleth - Users mailing list archive</a> at Nabble.com.<br/>