<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<META http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
<meta name="Generator" content="Microsoft Word 14 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
{font-family:Tahoma;
panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0cm;
margin-bottom:.0001pt;
font-size:11.0pt;
font-family:"Calibri","sans-serif";
mso-fareast-language:EN-US;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:#0563C1;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:#954F72;
text-decoration:underline;}
span.EmailStyle17
{mso-style-type:personal;
font-family:"Calibri","sans-serif";
color:windowtext;}
span.EmailStyle18
{mso-style-type:personal-reply;
font-family:"Calibri","sans-serif";
color:#1F497D;}
.MsoChpDefault
{mso-style-type:export-only;
font-size:10.0pt;}
@page WordSection1
{size:612.0pt 792.0pt;
margin:70.85pt 70.85pt 70.85pt 70.85pt;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-GB" link="#0563C1" vlink="#954F72">
<div class="WordSection1">
<p class="MsoNormal"><span style="color:#1F497D">Andre<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Can you not take on the SSL stage on the IdP? We are running our new v3 IdP behind ForeFront TMG, and imported our wildcard (*.srv.ourdomain) certificate into Jetty. We did try with Apache but were hitting issues.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">So if you’re deploying a v3, I highly suggest this approach.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">HTH,<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">Dave<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<div>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif";color:#1F497D;mso-fareast-language:EN-GB">_________________________________________________<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif";color:#1F497D;mso-fareast-language:EN-GB">Dave Perry<br>
eLearning Technologist, Hull College Group<br>
<br>
Room L34 - Queens Gardens Library<br>
Wilberforce Drive, Queen's Gardens, Hull, HU1 3DG<br>
Extension 2230 / Direct Dial 01482 381930<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif";color:#1F497D;mso-fareast-language:EN-GB"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif";color:#1F497D;mso-fareast-language:EN-GB">* Need a fast reply? Try
<a href="mailto:elearning@hull-college.ac.uk"><span style="color:blue">elearning@hull-college.ac.uk</span></a> *<o:p></o:p></span></p>
</div>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<div>
<div style="border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0cm 0cm 0cm">
<p class="MsoNormal" style="margin-left:36.0pt"><b><span lang="EN-US" style="font-size:10.0pt;font-family:"Tahoma","sans-serif";mso-fareast-language:EN-GB">From:</span></b><span lang="EN-US" style="font-size:10.0pt;font-family:"Tahoma","sans-serif";mso-fareast-language:EN-GB">
users [mailto:users-bounces@shibboleth.net] <b>On Behalf Of </b>Andrej Gregorka<br>
<b>Sent:</b> 21 September 2015 10:05<br>
<b>To:</b> 'users@shibboleth.net'<br>
<b>Subject:</b> Idp behind SSL endpoint without AJP (POSSIBLE SPAM)<o:p></o:p></span></p>
</div>
</div>
<p class="MsoNormal" style="margin-left:36.0pt"><o:p> </o:p></p>
<p class="MsoNormal" style="margin-left:36.0pt"><span lang="SL">I have IDP deployed behind SSL endpoint. If I connect to IDP using AJP everything works fine:<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:36.0pt;text-indent:35.4pt"><span lang="SL">ProxyPass /idp/ ajp:// xxx.xxx.xxx.xxx:8009/idp/
<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:36.0pt;text-indent:35.4pt"><span lang="SL">ProxyPassReverse /idp/ ajp:// xxx.xxx.xxx.xxx:8009/idp/
<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:36.0pt"><span lang="SL"><o:p> </o:p></span></p>
<p class="MsoNormal" style="margin-left:36.0pt"><span lang="SL"><o:p> </o:p></span></p>
<p class="MsoNormal" style="margin-left:36.0pt"><span lang="SL">However, I will not be able to use AJP in production, so I have to connect from proxy using http. If I change to http:<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:36.0pt"><span lang="SL"> ProxyPass /idp/
<a href="http://xxx.xxx.xxx.xxx.si:8080/idp/">http://xxx.xxx.xxx.xxx.si:8080/idp/</a>
<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:36.0pt"><span lang="SL"> ProxyPassReverse /idp/ http:// xxx.xxx.xxx.xxx:8080/idp/
<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:36.0pt"><span lang="SL"><o:p> </o:p></span></p>
<p class="MsoNormal" style="margin-left:36.0pt"><span lang="SL"><o:p> </o:p></span></p>
<p class="MsoNormal" style="margin-left:36.0pt"><span lang="SL">I get the following error in idp-process.log:<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:36.0pt"><span lang="SL">10:09:40.817 - ERROR [org.opensaml.common.binding.decoding.BaseSAMLMessageDecoder:215] - SAML message intended destination endpoint
<span style="color:red">'https</span>://domain/idp/profile/SAML2/Redirect/SSO' did not match the recipient endpoint
<span style="color:red">'http</span>:// domain /idp/profile/SAML2/Redirect/SSO'<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:36.0pt"><span lang="SL">10:09:40.818 - WARN [edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler:406] - Message did not meet security requirements<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:36.0pt"><span lang="SL"><o:p> </o:p></span></p>
<p class="MsoNormal" style="margin-left:36.0pt"><span lang="SL"><o:p> </o:p></span></p>
<p class="MsoNormal" style="margin-left:36.0pt"><span lang="SL">In idp-access.log:<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:36.0pt"><span lang="SL">20150921T084714Z|10.10.10.161|domain:80|/profile/SAML2/Redirect/SSO|<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-left:36.0pt"><span lang="SL"><o:p> </o:p></span></p>
<p class="MsoNormal" style="margin-left:36.0pt"><span lang="SL"><o:p> </o:p></span></p>
<p class="MsoNormal" style="margin-left:36.0pt"><span lang="SL">How can I get the IDP working behind proxy using the http connection?<o:p></o:p></span></p>
</div>
<div>
<font color="#999999" size="2">
<span style="font-family: Arial;"><a href="http://www.hull-college.ac.uk/about-us/stakeholders-newsletter">The Review Newsletter</a></span> </font></div><div><font color="#999999" size="2"><br />
<font face="Arial">This message is sent in confidence for the addressee </font>
<span style="font-family: Arial;">only. It may contain confidential or sensitive </span>
<span style="font-family: Arial;">information. The contents are not to be disclosed </span>
<span style="font-family: Arial;">to anyone other than the addressee. Unauthorised </span>
<span style="font-family: Arial;">recipients are requested to preserve this </span>
<span style="font-family: Arial;">confidentiality and to advise us of any errors in </span>
<span style="font-family: Arial;">transmission. Any views expressed in this message </span>
<span style="font-family: Arial;">are solely the views of the individual and do not </span>
<span style="font-family: Arial;">represent the views of the College. Nothing in this </span>
<span style="font-family: Arial;">message should be construed as creating a contract.</span>
</font>
</div>
<div>
<font face="Arial" color="#999999" size="2">
<br />
</font>
</div>
<div>
<font face="Arial" color="#999999" size="2">Hull College Group owns the email infrastructure, including the contents.</font>
</div>
<div>
<font face="Arial" color="#999999" size="2">
<br />
</font>
</div>
<div>
<font face="Arial" size="2" color="#00CC33">Hull College Group is committed to sustainability, please reflect before printing
this email.</font>
</div>
<div>
<hr />
</div>
</body>
</html>