<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<!--[if !mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]--><style><!--
/* Font Definitions */
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Tahoma;
        panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0cm;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;
        mso-fareast-language:EN-US;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:#0563C1;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:#954F72;
        text-decoration:underline;}
span.EmailStyle17
        {mso-style-type:personal;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
span.EmailStyle18
        {mso-style-type:personal;
        font-family:"Calibri",sans-serif;
        color:#1F497D;}
span.EmailStyle19
        {mso-style-type:personal-reply;
        font-family:"Calibri",sans-serif;
        color:#1F497D;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}
@page WordSection1
        {size:612.0pt 792.0pt;
        margin:70.85pt 70.85pt 70.85pt 70.85pt;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="SL" link="#0563C1" vlink="#954F72">
<div class="WordSection1">
<p class="MsoNormal"><span style="color:#1F497D">Hi Dave,<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Idp has to be behind SSL endpoint, we can't change that.
<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Andrej<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0cm 0cm 0cm">
<p class="MsoNormal"><b><span lang="EN-US" style="mso-fareast-language:SL">From:</span></b><span lang="EN-US" style="mso-fareast-language:SL"> users [mailto:users-bounces@shibboleth.net]
<b>On Behalf Of </b>Dave Perry<br>
<b>Sent:</b> Monday, September 21, 2015 11:15 AM<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Subject:</b> RE: Idp behind SSL endpoint without AJP (POSSIBLE SPAM)<o:p></o:p></span></p>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><span lang="EN-GB" style="color:#1F497D">Andre<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB" style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB" style="color:#1F497D">Can you not take on the SSL stage on the IdP? We are running our new v3 IdP behind ForeFront TMG, and imported our wildcard (*.srv.ourdomain) certificate into Jetty. We did try with Apache but were
 hitting issues.<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB" style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB" style="color:#1F497D">So if you’re deploying a v3, I highly suggest this approach.<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB" style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB" style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB" style="color:#1F497D">HTH,<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB" style="color:#1F497D">Dave<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB" style="color:#1F497D"><o:p> </o:p></span></p>
<div>
<p class="MsoNormal"><span lang="EN-GB" style="font-size:10.0pt;font-family:"Tahoma",sans-serif;color:#1F497D;mso-fareast-language:EN-GB">_________________________________________________<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB" style="font-size:10.0pt;font-family:"Tahoma",sans-serif;color:#1F497D;mso-fareast-language:EN-GB">Dave Perry<br>
eLearning Technologist, Hull College Group<br>
<br>
Room L34 - Queens Gardens Library<br>
Wilberforce Drive, Queen's Gardens, Hull, HU1 3DG<br>
Extension 2230 / Direct Dial 01482 381930<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB" style="font-size:10.0pt;font-family:"Tahoma",sans-serif;color:#1F497D;mso-fareast-language:EN-GB"><o:p> </o:p></span></p>
<p class="MsoNormal"><span lang="EN-GB" style="font-size:10.0pt;font-family:"Tahoma",sans-serif;color:#1F497D;mso-fareast-language:EN-GB">* Need a fast reply? Try
<a href="mailto:elearning@hull-college.ac.uk"><span style="color:blue">elearning@hull-college.ac.uk</span></a> *<o:p></o:p></span></p>
</div>
<p class="MsoNormal"><span lang="EN-GB" style="color:#1F497D"><o:p> </o:p></span></p>
<div>
<div style="border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0cm 0cm 0cm">
<p class="MsoNormal" style="margin-left:36.0pt"><b><span lang="EN-US" style="font-size:10.0pt;font-family:"Tahoma",sans-serif;mso-fareast-language:EN-GB">From:</span></b><span lang="EN-US" style="font-size:10.0pt;font-family:"Tahoma",sans-serif;mso-fareast-language:EN-GB">
 users [<a href="mailto:users-bounces@shibboleth.net">mailto:users-bounces@shibboleth.net</a>]
<b>On Behalf Of </b>Andrej Gregorka<br>
<b>Sent:</b> 21 September 2015 10:05<br>
<b>To:</b> 'users@shibboleth.net'<br>
<b>Subject:</b> Idp behind SSL endpoint without AJP (POSSIBLE SPAM)<o:p></o:p></span></p>
</div>
</div>
<p class="MsoNormal" style="margin-left:36.0pt"><span lang="EN-GB"><o:p> </o:p></span></p>
<p class="MsoNormal" style="margin-left:36.0pt">I have IDP deployed behind SSL endpoint. If I connect to IDP using AJP everything works fine:<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:36.0pt;text-indent:35.4pt">ProxyPass           /idp/           ajp:// xxx.xxx.xxx.xxx:8009/idp/   
<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:36.0pt;text-indent:35.4pt">ProxyPassReverse    /idp/           ajp:// xxx.xxx.xxx.xxx:8009/idp/  
<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:36.0pt"><o:p> </o:p></p>
<p class="MsoNormal" style="margin-left:36.0pt"><o:p> </o:p></p>
<p class="MsoNormal" style="margin-left:36.0pt">However, I will not be able to use AJP in production, so I have to connect from proxy using http. If I change to http:<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:36.0pt">          ProxyPass           /idp/          
<a href="http://xxx.xxx.xxx.xxx.si:8080/idp/">http://xxx.xxx.xxx.xxx.si:8080/idp/</a>   
<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:36.0pt">         ProxyPassReverse    /idp/           http:// xxx.xxx.xxx.xxx:8080/idp/        
<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:36.0pt"><o:p> </o:p></p>
<p class="MsoNormal" style="margin-left:36.0pt"><o:p> </o:p></p>
<p class="MsoNormal" style="margin-left:36.0pt">I get the following error in idp-process.log:<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:36.0pt">10:09:40.817 - ERROR [org.opensaml.common.binding.decoding.BaseSAMLMessageDecoder:215] - SAML message intended destination endpoint
<span style="color:red">'https</span>://domain/idp/profile/SAML2/Redirect/SSO' did not match the recipient endpoint
<span style="color:red">'http</span>:// domain /idp/profile/SAML2/Redirect/SSO'<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:36.0pt">10:09:40.818 - WARN [edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler:406] - Message did not meet security requirements<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:36.0pt"><o:p> </o:p></p>
<p class="MsoNormal" style="margin-left:36.0pt"><o:p> </o:p></p>
<p class="MsoNormal" style="margin-left:36.0pt">In idp-access.log:<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:36.0pt">20150921T084714Z|10.10.10.161|domain:80|/profile/SAML2/Redirect/SSO|<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:36.0pt"><o:p> </o:p></p>
<p class="MsoNormal" style="margin-left:36.0pt"><o:p> </o:p></p>
<p class="MsoNormal" style="margin-left:36.0pt">How can I get the IDP working behind proxy using the http connection?<o:p></o:p></p>
<div>
<p class="MsoNormal"><span lang="EN-GB" style="font-size:10.0pt;font-family:"Arial",sans-serif;color:#999999;mso-fareast-language:SL"><a href="http://www.hull-college.ac.uk/about-us/stakeholders-newsletter">The Review Newsletter</a></span><span lang="EN-GB" style="font-size:10.0pt;font-family:"Times New Roman",serif;color:#999999;mso-fareast-language:SL"> </span><span lang="EN-GB" style="font-size:12.0pt;font-family:"Times New Roman",serif;mso-fareast-language:SL"><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span lang="EN-GB" style="font-size:10.0pt;font-family:"Times New Roman",serif;color:#999999;mso-fareast-language:SL"><br>
</span><span lang="EN-GB" style="font-size:10.0pt;font-family:"Arial",sans-serif;color:#999999;mso-fareast-language:SL">This message is sent in confidence for the addressee </span><span lang="EN-GB" style="font-size:10.0pt;font-family:"Times New Roman",serif;color:#999999;mso-fareast-language:SL">
</span><span lang="EN-GB" style="font-size:10.0pt;font-family:"Arial",sans-serif;color:#999999;mso-fareast-language:SL">only.  It may contain confidential or sensitive </span><span lang="EN-GB" style="font-size:10.0pt;font-family:"Times New Roman",serif;color:#999999;mso-fareast-language:SL">
</span><span lang="EN-GB" style="font-size:10.0pt;font-family:"Arial",sans-serif;color:#999999;mso-fareast-language:SL">information.  The contents are not to be disclosed </span><span lang="EN-GB" style="font-size:10.0pt;font-family:"Times New Roman",serif;color:#999999;mso-fareast-language:SL">
</span><span lang="EN-GB" style="font-size:10.0pt;font-family:"Arial",sans-serif;color:#999999;mso-fareast-language:SL">to anyone other than the addressee.  Unauthorised </span><span lang="EN-GB" style="font-size:10.0pt;font-family:"Times New Roman",serif;color:#999999;mso-fareast-language:SL">
</span><span lang="EN-GB" style="font-size:10.0pt;font-family:"Arial",sans-serif;color:#999999;mso-fareast-language:SL">recipients are requested to preserve this </span><span lang="EN-GB" style="font-size:10.0pt;font-family:"Times New Roman",serif;color:#999999;mso-fareast-language:SL">
</span><span lang="EN-GB" style="font-size:10.0pt;font-family:"Arial",sans-serif;color:#999999;mso-fareast-language:SL">confidentiality and to advise us of any errors in </span><span lang="EN-GB" style="font-size:10.0pt;font-family:"Times New Roman",serif;color:#999999;mso-fareast-language:SL">
</span><span lang="EN-GB" style="font-size:10.0pt;font-family:"Arial",sans-serif;color:#999999;mso-fareast-language:SL">transmission.  Any views expressed in this message </span><span lang="EN-GB" style="font-size:10.0pt;font-family:"Times New Roman",serif;color:#999999;mso-fareast-language:SL">
</span><span lang="EN-GB" style="font-size:10.0pt;font-family:"Arial",sans-serif;color:#999999;mso-fareast-language:SL">are solely the views of the individual and do not </span><span lang="EN-GB" style="font-size:10.0pt;font-family:"Times New Roman",serif;color:#999999;mso-fareast-language:SL">
</span><span lang="EN-GB" style="font-size:10.0pt;font-family:"Arial",sans-serif;color:#999999;mso-fareast-language:SL">represent the views of the College.  Nothing in this </span><span lang="EN-GB" style="font-size:10.0pt;font-family:"Times New Roman",serif;color:#999999;mso-fareast-language:SL">
</span><span lang="EN-GB" style="font-size:10.0pt;font-family:"Arial",sans-serif;color:#999999;mso-fareast-language:SL">message should be construed as creating a contract.</span><span lang="EN-GB" style="font-size:10.0pt;font-family:"Times New Roman",serif;color:#999999;mso-fareast-language:SL">
</span><span lang="EN-GB" style="font-size:12.0pt;font-family:"Times New Roman",serif;mso-fareast-language:SL"><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span lang="EN-GB" style="font-size:12.0pt;font-family:"Times New Roman",serif;mso-fareast-language:SL"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span lang="EN-GB" style="font-size:10.0pt;font-family:"Arial",sans-serif;color:#999999;mso-fareast-language:SL">Hull College Group owns the email infrastructure, including the contents.</span><span lang="EN-GB" style="font-size:12.0pt;font-family:"Times New Roman",serif;mso-fareast-language:SL">
<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span lang="EN-GB" style="font-size:12.0pt;font-family:"Times New Roman",serif;mso-fareast-language:SL"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span lang="EN-GB" style="font-size:10.0pt;font-family:"Arial",sans-serif;color:#00CC33;mso-fareast-language:SL">Hull College Group is committed to sustainability, please reflect before printing this email.</span><span lang="EN-GB" style="font-size:12.0pt;font-family:"Times New Roman",serif;mso-fareast-language:SL">
<o:p></o:p></span></p>
</div>
<div>
<div class="MsoNormal" align="center" style="text-align:center"><span lang="EN-GB" style="font-size:12.0pt;font-family:"Times New Roman",serif;mso-fareast-language:SL">
<hr size="2" width="100%" align="center">
</span></div>
</div>
</div>
</body>
</html>