<div dir="ltr">Okay Scott, <div>So I read the documentation and did below config:</div><div> </div><div> 1. I configured the remoteuser-internal-authn-config.xml to load remote user header</div><div> <b> <util:list id="shibboleth.authn.RemoteUser.checkHeaders"></b></div><div><b> <value>X-REMOTE_USER</value></b></div><div><b> </util:list></b><br></div><div><b><br></b></div><div> 2. Configured the RemoteUserAuth servlets init param value.</div><div> </div><div> <b><init-param></b></div><div><b> <param-name>checkHeaders</param-name></b></div><div><b> <param-value>X-REMOTE-USER</param-value></b></div><div><b> </init-param></b></div><div><b><br></b></div><div><b> 3</b>. After authenting the user via apache, on redirecting to IDP I get below error:</div><div><br></div><div> <b> "No conversation key found."</b></div><div><br></div><div> So, I tried to hard code the some key value like e1s1 in the url like below </div><div> </div><div> <b> <a href="http://mytest.com/idp/Authn/RemoteUser?conversation=%e1s1%22">http://mytest.com/idp/Authn/RemoteUser?conversation=%e1s1%22</a></b></div><div><br></div><div> But after that IDP throws:</div><div><br></div><div> <b>ERROR [net.shibboleth.idp.authn.ExternalAuthenticationException:76] -</b></div><div><b>net.shibboleth.idp.authn.ExternalAuthenticationException: No conversation state found in session for key ("els1")</b></div><div><b> </b></div><div><br></div><div> 4. apache is sending back the remote user name in headers to IDP .</div><div> <b>apache http server access log: " testuser [04/Aug/2017:07:05:13 -0400] "POST /idp/ HTTP/1.1" 302 230"</b></div><div><b><br></b></div><div> let me know , how to resolve this?? Actually in the documentation it is mentioned like when remote user is present in the http header then remoteUserServlet will consider the user as authenticated and will release the attributes for the user. But why the IDP needs conversation key here... So do I miss any other configurations ??</div><div><br></div><div>Thanks in advance..</div><div><br></div><div> </div><div><br></div></div><div class="gmail_extra"><br><div class="gmail_quote">On Thu, Aug 3, 2017 at 1:22 PM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">> We already have IDP V2, instead of upgrading to v 3.3 we are building it from<br>
> scratch...<br>
<br>
</span>Then you're guaranteeing problems, basically. Remember that I said that when it breaks and you can't get it to behave like it did before.<br>
<span class=""><br>
> How do I make IDP to check headers during remote user authentication.<br>
<br>
</span>Did you read the documentation on the login method you're trying to use? Ask a specific question if something isn't clear. I won't repeat the documentation here.<br>
<span class="HOEnZb"><font color="#888888"><br>
-- Scott<br>
</font></span><div class="HOEnZb"><div class="h5"><br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br>
</div></div></blockquote></div><br><br clear="all"><div><br></div>-- <br><div class="gmail_signature" data-smartmail="gmail_signature">*Best wishes*,<br>*Satheesh K*<br><br><br><br></div>
</div>