<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 14 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Verdana;
        panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
span.EmailStyle17
        {mso-style-type:personal-compose;
        font-family:"Calibri","sans-serif";
        color:windowtext;}
span.servicename
        {mso-style-name:service_name;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-family:"Calibri","sans-serif";}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal"><span style="font-size:12.0pt;color:#403152">Hello Team,<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal">I have been trying to setup SSO to test with Shibboleth SP(2.5.5) and IDP(3.1.2) along with Apache DS(2.0M20) ; Apache WS (2.4.16) ; Tomcat7 and self-signed certificate for SSL. After so much effort I am able to integrate all these but
 unable to get the success page. All setup is done locally on Windows m/c. I have few challenges to overcome and need your guide for the same.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">1} First, Once I am able to login successfully then how I can be able to access other Apps (URLs) without the authentication ; In short where to define Accessible Applications and restrict roles?
<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">2) When I am trying to access via ECP (<a href="https://xample.fissso.org/idp-web/profile/SAML2/SOAP/ECP">https://xample.fissso.org/idp-web/profile/SAML2/SOAP/ECP</a>)  then after entering valid uid/pwd getting the below error :<o:p></o:p></p>
<p class="MsoNormal">HTTP Status 403 - Access to the requested resource has been denied<o:p></o:p></p>
<p class="MsoNormal">IDP logs - INFO [net.shibboleth.utilities.java.support.security.BasicKeystoreKeyStrategy:327] - [] - Default key version has not changed, still secret1<o:p></o:p></p>
<p class="MsoNormal">Ap24 logs - 127.0.0.1 - - [30/Sep/2015:19:35:04 +0530] "GET /idp-web/profile/SAML2/SOAP/ECP HTTP/1.1" 403 1108<o:p></o:p></p>
<p class="MsoNormal">Tomcat logs - 127.0.0.1 - 123 [30/Sep/2015:19:35:04 +0530] "GET /idp-web/profile/SAML2/SOAP/ECP HTTP/1.1" 403 1108<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">3) When I am trying to access via login (xample.fissso.org/idp-web/login) then its redirect me to the below url for consent:<o:p></o:p></p>
<p class="MsoNormal"><a href="https://xample.fissso.org/idp-web/profile/SAML2/Redirect/SSO?execution=e2s1">https://xample.fissso.org/idp-web/profile/SAML2/Redirect/SSO?execution=e2s1</a><o:p></o:p></p>
<p class="MsoNormal">like below - <o:p></o:p></p>
<p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Verdana","sans-serif";color:black;background:white">You are about to access the service:
</span><span style="font-size:9.0pt;font-family:"Verdana","sans-serif";color:black"><br>
<span class="servicename"><b><span style="background:white">xample.fissso.org</span></b></span></span><o:p></o:p></p>
<table class="MsoNormalTable" border="0" cellspacing="0" cellpadding="0" style="border-collapse:collapse">
<tbody>
<tr style="height:12.6pt">
<td width="351" valign="top" style="width:263.05pt;border:solid windowtext 1.0pt;padding:0in 5.4pt 0in 5.4pt;height:12.6pt">
<p class="MsoNormal">Information to be Provided to Service<o:p></o:p></p>
</td>
</tr>
<tr style="height:12.6pt">
<td width="351" valign="top" style="width:263.05pt;border:solid windowtext 1.0pt;border-top:none;padding:0in 5.4pt 0in 5.4pt;height:12.6pt">
<p class="MsoNormal">cn                                                           123        
<o:p></o:p></p>
</td>
</tr>
<tr style="height:12.6pt">
<td width="351" valign="top" style="width:263.05pt;border:solid windowtext 1.0pt;border-top:none;padding:0in 5.4pt 0in 5.4pt;height:12.6pt">
<p class="MsoNormal">eduPersonPrincipalName            <a href="mailto:123@FNFIS.com">
123@FNFIS.com</a>               <o:p></o:p></p>
</td>
</tr>
<tr style="height:12.6pt">
<td width="351" valign="top" style="width:263.05pt;border:solid windowtext 1.0pt;border-top:none;padding:0in 5.4pt 0in 5.4pt;height:12.6pt">
<p class="MsoNormal">mail                                                        <a href="mailto:123@example.org">
123@example.org</a>           <o:p></o:p></p>
</td>
</tr>
<tr style="height:12.6pt">
<td width="351" valign="top" style="width:263.05pt;border:solid windowtext 1.0pt;border-top:none;padding:0in 5.4pt 0in 5.4pt;height:12.6pt">
<p class="MsoNormal">sn                                                           123        
<o:p></o:p></p>
</td>
</tr>
<tr style="height:12.6pt">
<td width="351" valign="top" style="width:263.05pt;border:solid windowtext 1.0pt;border-top:none;padding:0in 5.4pt 0in 5.4pt;height:12.6pt">
<p class="MsoNormal">uid                                                          123
<o:p></o:p></p>
</td>
</tr>
</tbody>
</table>
<p class="MsoNormal"><span style="font-size:9.0pt;font-family:"Verdana","sans-serif";color:black;background:#F6F6F6">Select an information release consent duration:…….<o:p></o:p></span></p>
<p class="MsoNormal">Although the above details are NOT matched with user information stored in LDAP.<br>
After accepting the consent redirected to “HTTP Status 404 - /idp-web/login” with blank page.URL (<a href="https://xample.fissso.org/idp-web/login">https://xample.fissso.org/idp-web/login</a>)<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">4) Not sure if this is getting able to connect to ApacheDS to get authenticated because there is nothing in the DS logs when I am using below details in httpd.conf –<o:p></o:p></p>
<p class="MsoNormal"><Location /idp-web/*>    AuthType shibboleth<o:p></o:p></p>
<p class="MsoNormal">                   ShibRequestSetting requireSession 1<o:p></o:p></p>
<p class="MsoNormal">                   ShibUseHeaders On<o:p></o:p></p>
<p class="MsoNormal">                   require valid-user         </Location><o:p></o:p></p>
<p class="MsoNormal">But when I am explicitly setting the below values – <o:p></o:p></p>
<p class="MsoNormal" style="text-indent:.5in"><Location /idp-web/profile/SAML2/SOAP/ECP>  AuthName "LDAP FIS Test Login"<o:p></o:p></p>
<p class="MsoNormal">                AuthType Basic<o:p></o:p></p>
<p class="MsoNormal">                AuthBasicProvider ldap<o:p></o:p></p>
<p class="MsoNormal" style="text-indent:.5in">AuthLDAPURL ldap://ads.fissso.org:10389/ou=users,ou=system?*??(objectClass=*)<o:p></o:p></p>
<p class="MsoNormal">                AuthLDAPBindAuthoritative off<o:p></o:p></p>
<p class="MsoNormal">                LDAPReferrals Off<o:p></o:p></p>
<p class="MsoNormal" style="text-indent:.5in">require valid-user            </Location><o:p></o:p></p>
<p class="MsoNormal">I am able to get below the DS logs -<o:p></o:p></p>
<p class="MsoNormal">[21:01:47] WARN [org.apache.directory.server.core.normalization.NormalizationInterceptor] - undefined filter based on undefined attributeType not evaluted at all.  Returning empty enumeration.<o:p></o:p></p>
<p class="MsoNormal">This seems to be because of * at the place of uid in the given LDAP URL; not sure how to overcome with this problem.<o:p></o:p></p>
<p class="MsoNormal">Interestingly, if I pass wrong credential (Not matcing with Ldap) then it is asking again and in case pass the correct credential (@ECP url) then throwing below error as said above –
<o:p></o:p></p>
<p class="MsoNormal">HTTP Status 403 - Access to the requested resource has been denied<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">I have tried many ways to overcome with above issues but unable to get success page.  Below are config details I have provided in the setup –
<o:p></o:p></p>
<table class="MsoNormalTable" border="0" cellspacing="0" cellpadding="0" style="border-collapse:collapse">
<tbody>
<tr style="height:13.5pt">
<td width="311" valign="top" style="width:233.6pt;border:solid windowtext 1.0pt;padding:0in 5.4pt 0in 5.4pt;height:13.5pt">
<p class="MsoNormal">IDP Properties<o:p></o:p></p>
</td>
<td width="436" valign="top" style="width:327.1pt;border:solid windowtext 1.0pt;border-left:none;padding:0in 5.4pt 0in 5.4pt;height:13.5pt">
<p class="MsoNormal">LDAP.properties<o:p></o:p></p>
</td>
</tr>
<tr style="height:175.5pt">
<td width="311" valign="top" style="width:233.6pt;border:solid windowtext 1.0pt;border-top:none;padding:0in 5.4pt 0in 5.4pt;height:175.5pt">
<p class="MsoNormal">idp.entityID= <a href="https://xample.fissso.org/idp-web/shibboleth">
https://xample.fissso.org/idp-web/shibboleth</a><o:p></o:p></p>
<p class="MsoNormal">idp.scope= FNFIS.com<o:p></o:p></p>
<p class="MsoNormal">idp.views = %{idp.home}/views<o:p></o:p></p>
<p class="MsoNormal">idp.authn.flows= RemoteUserInternal<o:p></o:p></p>
<p class="MsoNormal">idp.authn.favorSSO = true<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
</td>
<td width="436" valign="top" style="width:327.1pt;border-top:none;border-left:none;border-bottom:solid windowtext 1.0pt;border-right:solid windowtext 1.0pt;padding:0in 5.4pt 0in 5.4pt;height:175.5pt">
<p class="MsoNormal">idp.authn.LDAP.authenticator= adAuthenticator<o:p></o:p></p>
<p class="MsoNormal">idp.authn.LDAP.ldapURL  = ldap://ads.fissso.org:10389<o:p></o:p></p>
<p class="MsoNormal">idp.authn.LDAP.useStartTLS     = false<o:p></o:p></p>
<p class="MsoNormal">idp.authn.LDAP.useSSL          = false<o:p></o:p></p>
<p class="MsoNormal">idp.authn.LDAP.sslConfig      = jvmTrust<o:p></o:p></p>
<p class="MsoNormal">idp.authn.LDAP.baseDN  =  ou=users,ou=system<o:p></o:p></p>
<p class="MsoNormal">idp.authn.LDAP.bindDN   = uid=321<o:p></o:p></p>
<p class="MsoNormal">idp.authn.LDAP.bindDNCredential   = test#ldap<o:p></o:p></p>
<p class="MsoNormal">idp.authn.LDAP.returnAttributes= uid,cn,sn<o:p></o:p></p>
<p class="MsoNormal">idp.authn.LDAP.subtreeSearch      = true<o:p></o:p></p>
<p class="MsoNormal">idp.authn.LDAP.userFilter       = (uid={user})<o:p></o:p></p>
<p class="MsoNormal">idp.authn.LDAP.dnFormat= uid=%s,ou=users,ou=system <o:p></o:p></p>
</td>
</tr>
</tbody>
</table>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Along with attribute settings changes in Relying-party.xml details are  - <util:list id="shibboleth.RelyingPartyOverrides"><o:p></o:p></p>
<p class="MsoNormal">        <bean parent="RelyingPartyByName" c:relyingPartyIds="<a href="https://xample.fissso.org/shibboleth">https://xample.fissso.org/shibboleth</a>"><o:p></o:p></p>
<p class="MsoNormal">            <property name="profileConfigurations"><o:p></o:p></p>
<p class="MsoNormal">                <list>                  <bean parent="SAML2.SSO" p:encryptAssertions="false" p:postAuthenticationFlows="attribute-release"/><o:p></o:p></p>
<p class="MsoNormal">                </list>            </property>        </bean>    </util:list><o:p></o:p></p>
<p class="MsoNormal">Also provided SP and IDP metadata in the metadata folder of IDP and  IDP’s metadata in SP – etc / shib/ path and in the logs it is loaded successful.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">I am able to see the default pages like – index and status page and able to see the request reached to tomcat when access default pages.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><span style="font-size:12.0pt;color:#403152">It will be great if you can guide me further to overcome the above said problems / deadlock and see the success.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:12.0pt;color:#403152"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:12.0pt;color:#403152">Thanks & Best Regards,<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:12.0pt;color:#403152">Himanshu Gaur<o:p></o:p></span></p>
</div>

<DIV>
_____________<BR>
The information contained in this message is proprietary and/or confidential. If you are not the intended recipient, please: (i) delete the message and all copies; (ii) do not disclose, distribute or use the message in any manner; and (iii) notify the sender immediately. In addition, please be aware that any message addressed to our domain is subject to archiving and review by persons other than the intended recipient. Thank you.<BR>
</DIV></body>
</html>