<div dir="ltr"><span style="color:rgb(0,0,0);font-size:12.8px">Hi,</span><div style="color:rgb(0,0,0);font-size:12.8px"><br></div><div style="color:rgb(0,0,0);font-size:12.8px">I am trying to implement a basic SSO using Shibboleth SP 2.6.0.1 with Apache web server 2.4 and Shibboleth IDP 3.3.0.</div><div style="color:rgb(0,0,0);font-size:12.8px"><br></div><div style="color:rgb(0,0,0);font-size:12.8px">I have successfully tested both SP and IDP with these URLs with successful response.</div><div style="color:rgb(0,0,0);font-size:12.8px"><br></div><div style="color:rgb(0,0,0);font-size:12.8px">Service provider:(Running in Apache web server with port 443)</div><div style="color:rgb(0,0,0);font-size:12.8px"><i><a href="https://sp.example.org/Shibboleth.sso/Status" target="_blank">https://sp.example.org/<wbr>Shibboleth.sso/Status</a></i></div><div style="color:rgb(0,0,0);font-size:12.8px"><br></div><div style="color:rgb(0,0,0);font-size:12.8px">Identity provider:(Running in Tomcat with port 8443)</div><div style="color:rgb(0,0,0);font-size:12.8px"><i><a href="https://localhost:8443/idp/profile/status" target="_blank">https://localhost:8443/idp/<wbr>profile/status</a></i></div><div style="color:rgb(0,0,0);font-size:12.8px">(Domain name of both SP and IDP have been mapped to 127.0.0.1 is host file)</div><div style="color:rgb(0,0,0);font-size:12.8px">I am trying to secure one folder in the document root of my Apache web server by adding this in apache24.config file(Supplied by Shibboleth) which is included in apache configuration.</div><div style="color:rgb(0,0,0);font-size:12.8px"><div><i><font color="#000000" style="background-color:rgb(255,255,0)"><Location /secure></font></i></div><div><i><font color="#000000" style="background-color:rgb(255,255,0)"><span class="gmail-m_-6288806540260368564gmail-Apple-tab-span" style="white-space:pre-wrap">     </span>AuthType shibboleth</font></i></div><div><i><font color="#000000" style="background-color:rgb(255,255,0)"><span class="gmail-m_-6288806540260368564gmail-Apple-tab-span" style="white-space:pre-wrap">   </span>ShibRequireSession On</font></i></div><div><i><font color="#000000" style="background-color:rgb(255,255,0)"><span class="gmail-m_-6288806540260368564gmail-Apple-tab-span" style="white-space:pre-wrap"> </span>require valid-user</font></i></div><div><i><font color="#000000" style="background-color:rgb(255,255,0)"></Location></font></i></div><div><br></div><div>When I am hitting this URL <b><a href="https://localhost/secure/index.html" target="_blank">https://localhost/secure/<wbr>index.html</a>, </b> the request is getting redirected to my IDP with this URL in browser. (Strange part is this URL has the domain  name of my IDP but it doesn't have the port where IDP is running[8443]. So I think as port number is missing, it's trying to hit the same Apache web server with default port 443 where SP is running and obviously this URL won't be valid. This is my thinking, please rectify if wrong)<br><i><a href="https://ushydbhapanda1.us.deloitte.com/idp/profile/SAML2/Redirect/SSO?SAMLRequest=fZJLb8IwEIT%2FSuQ7cR6UUosgBXIAqYWIQKX2UjnOllhy7NTr9PHvG14tvfS8szM7n3aCvFEtSztX6w28dYDO%2B2yURnYcJKSzmhmOEpnmDSBzghXpwz2L%2FIC11jgjjCJeigjWSaPnRmPXgC3AvksBu819QmrnWmSUKiO4qg06WtSyLI0CV%2FuIhh4MI5qviy3xsv4CqfnB63dzVyyestkizdNVloZ%2Bh34FykjnwBemobJqaX%2FLq1Rw9tpAJS2IPqlYE2%2BZJeTlRgSjEOIoHsOoDMNKQFmWwe3deCzGMQRBL0PsYKnRce0SEgXh7SCIB0G0DWMWD9kwfCZefq48k7qSev8%2Fn%2FIkQrbYbvPBqd8jWDx26wVkOjlQZsdge8X9f1t%2BgU2mF0DY%2BvDJm1aBb%2Bye4g%2FfCb1KOMW1bNVbLrPcKCm%2BvFQp8zG3wB0kJCR0elr5%2BxPTbw%3D%3D&RelayState=ss%3Amem%3Adc0eb9da120e80e9fe089fe185da947596c266d3bb8ec5d82108dfd17464b6a0" target="_blank">https://ushydbhapanda1.us.<wbr>deloitte.com/idp/profile/<wbr>SAML2/Redirect/SSO?<wbr>SAMLRequest=fZJLb8IwEIT%<wbr>2FSuQ7cR6UUosgBXIAqYWIQKX2UjnO<wbr>llhy7NTr9PHvG14tvfS8szM7n3aCvF<wbr>EtSztX6w28dYDO%<wbr>2B2yURnYcJKSzmhmOEpnmDSBzghXpw<wbr>z2L%<wbr>2FIC11jgjjCJeigjWSaPnRmPXgC3Av<wbr>ksBu819QmrnWmSUKiO4qg06WtSyLI0<wbr>CV%<wbr>2FuIhh4MI5qviy3xsv4CqfnB63dzVy<wbr>yestkizdNVloZ%<wbr>2Bh34FykjnwBemobJqaX%<wbr>2FLq1Rw9tpAJS2IPqlYE2%<wbr>2BZJeTlRgSjEOIoHsOoDMNKQFmWwe3<wbr>deCzGMQRBL0PsYKnRce0SEgXh7SCIB<wbr>0G0DWMWD9kwfCZefq48k7qSev8%<wbr>2Fn%<wbr>2FIkQrbYbvPBqd8jWDx26wVkOjlQZs<wbr>dge8X9f1t%2BgU2mF0DY%<wbr>2BvDJm1aBb%2Bye4g%<wbr>2FfCb1KOMW1bNVbLrPcKCm%<wbr>2BvFQp8zG3wB0kJCR0elr5%<wbr>2BxPTbw%3D%3D&RelayState=ss%<wbr>3Amem%<wbr>3Adc0eb9da120e80e9fe089fe185da<wbr>947596c266d3bb8ec5d82108dfd174<wbr>64b6a0</a></i><br></div><div><br></div><div>And I am getting this response<br><h1><span style="background-color:rgb(208,224,227)">Not Found</span></h1><p><span style="background-color:rgb(208,224,227)">The requested URL /idp/profile/SAML2/Redirect/<wbr>SSO was not found on this server.</span><br><br>And nothing is getting updated in any log of IDP.(idp-warn.log or idp-process.log).</p><p><br></p><p>For your information, I can see the SAML authentication request being generated in SP shibd.log. Here is the log.</p><p><span style="background-color:rgb(255,255,0)">2017-03-02 19:02:49 DEBUG Shibboleth.Listener [4]: dispatching message (default::getHeaders::<wbr>Application)<br>2017-03-02 19:02:49 DEBUG Shibboleth.Listener [4]: dispatching message (default/Login::run::SAML2SI)<br>2017-03-02 19:02:49 DEBUG XMLTooling.StorageService [4]: inserted record (<wbr>2c6aad9c474bf8f6a36331a8617adc<wbr>7d31cc9b6e0d0f7d7c3d1ce4bbb8e4<wbr>72f2) in context (RelayState) with expiration (1488462169)<br>2017-03-02 19:02:49 DEBUG OpenSAML.MessageEncoder.<wbr>SAML2Redirect [4]: validating input<br>2017-03-02 19:02:49 DEBUG OpenSAML.MessageEncoder.<wbr>SAML2Redirect [4]: marshalling, deflating, base64-encoding the message<br>2017-03-02 19:02:49 DEBUG OpenSAML.MessageEncoder.<wbr>SAML2Redirect [4]: marshalled message:<br><samlp:AuthnRequest xmlns:samlp="urn:oasis:names:<wbr>tc:SAML:2.0:protocol" AssertionConsumerServiceURL="<a href="https://localhost/Shibboleth.sso/SAML2/POST" target="_blank">h<wbr>ttps://localhost/Shibboleth.<wbr>sso/SAML2/POST</a>" Destination="<a href="https://ushydbhapanda1.us.deloitte.com/idp/profile/SAML2/Redirect/SSO" target="_blank">https://<wbr>USHYDBHAPANDA1.us.deloitte.<wbr>com/idp/profile/SAML2/<wbr>Redirect/SSO</a>" ID="_<wbr>ac9f6e4583b05af0e864068313f498<wbr>ed" IssueInstant="2017-03-02T13:<wbr>32:49Z" ProtocolBinding="urn:oasis:<wbr>names:tc:SAML:2.0:bindings:<wbr>HTTP-POST" Version="2.0"><saml:Issuer xmlns:saml="urn:oasis:names:<wbr>tc:SAML:2.0:assertion"><a href="https://sp.example.org/shibboleth" target="_blank">https:/<wbr>/sp.example.org/shibboleth</a></<wbr>saml:Issuer><samlp:<wbr>NameIDPolicy AllowCreate="1"/></samlp:<wbr>AuthnRequest><br>2017-03-02 19:02:49 DEBUG OpenSAML.MessageEncoder.<wbr>SAML2Redirect [4]: message encoded, sending redirect to client<br>2017-03-02 19:04:41 DEBUG Shibboleth.Listener [4]: dispatching message (default/Login::run::SAML2SI)<br>2017-03-02 19:04:41 DEBUG XMLTooling.StorageService [4]: inserted record (<wbr>dc0eb9da120e80e9fe089fe185da94<wbr>7596c266d3bb8ec5d82108dfd17464<wbr>b6a0) in context (RelayState) with expiration (1488462281)<br>2017-03-02 19:04:41 DEBUG OpenSAML.MessageEncoder.<wbr>SAML2Redirect [4]: validating input<br>2017-03-02 19:04:41 DEBUG OpenSAML.MessageEncoder.<wbr>SAML2Redirect [4]: marshalling, deflating, base64-encoding the message<br>2017-03-02 19:04:41 DEBUG OpenSAML.MessageEncoder.<wbr>SAML2Redirect [4]: marshalled message:<br><samlp:AuthnRequest xmlns:samlp="urn:oasis:names:<wbr>tc:SAML:2.0:protocol" AssertionConsumerServiceURL="<a href="https://localhost/Shibboleth.sso/SAML2/POST" target="_blank">h<wbr>ttps://localhost/Shibboleth.<wbr>sso/SAML2/POST</a>" Destination="<a href="https://ushydbhapanda1.us.deloitte.com/idp/profile/SAML2/Redirect/SSO" target="_blank">https://<wbr>USHYDBHAPANDA1.us.deloitte.<wbr>com/idp/profile/SAML2/<wbr>Redirect/SSO</a>" ID="_<wbr>5c061e3238e6b11dcebbb07988c83e<wbr>00" IssueInstant="2017-03-02T13:<wbr>34:41Z" ProtocolBinding="urn:oasis:<wbr>names:tc:SAML:2.0:bindings:<wbr>HTTP-POST" Version="2.0"><saml:Issuer xmlns:saml="urn:oasis:names:<wbr>tc:SAML:2.0:assertion"><a href="https://sp.example.org/shibboleth" target="_blank">https:/<wbr>/sp.example.org/shibboleth</a></<wbr>saml:Issuer><samlp:<wbr>NameIDPolicy AllowCreate="1"/></samlp:<wbr>AuthnRequest><br>2017-03-02 19:04:41 DEBUG OpenSAML.MessageEncoder.<wbr>SAML2Redirect [4]: message encoded, sending redirect to client</span></p></div><div><div class="gmail-m_-6288806540260368564gmail_signature"><div dir="ltr"><div><div><div>Can anyone help me with this issue please ? I have to prepare this demo within few days.</div><div><i><br></i></div><div><i>Thanks and regards,</i><br><br></div><b>Bhawani shankar Panda</b><br></div>Application developer,<br>Deloitte USI consulting,</div><div>Hyderabad, India</div></div></div></div></div><div><div class="gmail_signature"><div dir="ltr"><div><div><div><div><i>Thanks and regards,</i><br></div></div></div></div><br></div></div></div>
</div>