<div dir="ltr"><div><div><div><div><div>Thanks for your reply.</div><div><br></div><div>So, I put the following into my shibboleth2.xml:<br><br><Path name="eds" authType="shibboleth" requireSession="false"/><br><br></div>Which I think is what I need (i know you said IIS config). But no luck.<br><br></div>But thinking about it, the eds will be used on my website.<br></div>Shibboleth and my website are on totally different<br></div>servers - does that actually make it easier? Or is it impossible<br></div>to have that setup?<br><br><div><br></div><div>Thanks.</div></div><div class="gmail_extra"><br><div class="gmail_quote">On Fri, Feb 2, 2018 at 3:50 PM, Robert Bradley <span dir="ltr"><<a href="mailto:robert.bradley@it.ox.ac.uk" target="_blank">robert.bradley@it.ox.ac.uk</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">-----BEGIN PGP SIGNED MESSAGE-----<br>
Hash: SHA256<br>
<br>
On 02/02/18 15:21, Chanda Banda wrote:<br>
> HI,<br>
><br>
> Im trying to get the EDS working. Ive followed the instructions so<br>
> in my shibboleth2.xml I have:<br>
><br>
> <SSO discoveryProtocol="SAMLDS" discoveryURL="<br>
> <a href="https://MYDOMAIN/shibboleth/eds/index.html" rel="noreferrer" target="_blank">https://MYDOMAIN/shibboleth/<wbr>eds/index.html</a>"> SAML2 SAML1 </SSO><br>
><br>
> and<br>
><br>
> <MetadataProvider type="XML" uri="<br>
> <a href="http://metadata.ukfederation.org.uk/ukfederation-metadata.xml" rel="noreferrer" target="_blank">http://metadata.ukfederation.<wbr>org.uk/ukfederation-metadata.<wbr>xml</a>"<br>
> backingFilePath="ukfederation-<wbr>metadata.xml" reloadInterval="14400"<br>
> legacyOrgNames="true"> <MetadataFilter type="RequireValidUntil"<br>
> maxValidityInterval="2592000"/<wbr>> <MetadataFilter type="Signature"<br>
> certificate="ukfederation.pem"<wbr>/> </MetadataProvider><br>
><br>
> One thing I am unsure about is that the documentation has a<br>
> different URI and backingFilePath???<br>
><br>
> <MetadataProvider type="XML" uri="<a href="http://federation/metadata.xml" rel="noreferrer" target="_blank">http://federation/<wbr>metadata.xml</a>"<br>
> <<a href="http://federation/metadata.xml" rel="noreferrer" target="_blank">http://federation/metadata.<wbr>xml</a>> backingFilePath="federation.<wbr>xml"<br>
> legacyOrgNames="true" reloadInterval="7200"<br>
<br>
<br>
The URL here is a placeholder for a real metadata location (e.g. the<br>
UK federation URL you're currently using).<br>
<br>
><br>
> Anyhow, qith my settings when I go to:<br>
><br>
> <a href="https://MYDOMAIN/Shibboleth.sso/Login" rel="noreferrer" target="_blank">https://MYDOMAIN/Shibboleth.<wbr>sso/Login</a><br>
><br>
> I get redirected to:<br>
><br>
> <a href="https://MYDOMAIN/shibboleth/eds/Index.html?entityID=https%3A%2F%2FMYDO
MAIN%2Fshibboleth&return=https%3A%2F%2FMYDOMAIN" rel="noreferrer" target="_blank">https://MYDOMAIN/shibboleth/<wbr>eds/Index.html?entityID=https%<wbr>3A%2F%2FMYDO<br>
MAIN%2Fshibboleth&return=<wbr>https%3A%2F%2FMYDOMAIN</a><br>
><br>
><br>
etcetcetcetcetc<br>
><br>
> And then I get the error message:<br>
><br>
> *The page isn’t redirecting properly* Any advice appreciated.<br>
<br>
Most likely the EDS pages are also being protected by Shibboleth, and<br>
so you end up in a continuous loop. You probably want to add the<br>
following to your Apache configuration:<br>
<br>
# Needed for embedded DS to work<br>
<Location /shibboleth/eds><br>
AuthType Shibboleth<br>
ShibRequestSetting requireSession 0<br>
Require all granted<br>
</Location><br>
<br>
to unprotect just the EDS pages and restart Apache. (If this is using<br>
IIS instead of Apache, similar advice applies, but the specific<br>
configuration needed will be different.)<br>
<br>
- --<br>
Dr Robert Bradley<br>
Identity and Access Management Team, IT Services, University of Oxford<br>
-----BEGIN PGP SIGNATURE-----<br>
<br>
iQIzBAEBCAAdFiEEgF3NFfO9FqlA+<wbr>ME+<wbr>lGGnynav474FAlp0iK0ACgkQlGGnyn<wbr>av<br>
475nQw/+<wbr>IEKJ17srTLtLsbrABD0JJDmZFFsZQe<wbr>42sbVMNYIPVkJZ/imto7uV/Xck<br>
9goDY/<wbr>VSH4OqUXWvxAzRo3zfoVxVXBRtKyHh<wbr>4z7KuHjeGlVFBzs0pvjmnGo97Djt<br>
7EWa3vXuXh3AbM/YN8TQrMOZ1s/<wbr>4QKCrCMMRWLFpj47f8um/<wbr>TtWgWb6aWwyvN4T4<br>
TsnxBPbNjamjmC4RPFl3arsY36ldAL<wbr>Et78Af0U6iYTEyUHvm2Ctbzi0BY8mv<wbr>RZI9<br>
3BMFoisXA7+<wbr>G6fZTPP7ZRJpMTK8XjaoeOU5BhpLQM<wbr>kN78N6Q5Yu/1TUZ1ewi0AKS<br>
xTELjl8CObO0VyRXvauaq94Or2P/<wbr>ySGHHcv3FwXHsbpllu9gmNjZ1EFl7x<wbr>z6VtZJ<br>
Gd05sbxaLEZkMiCMpjO5e9B6TA3QoT<wbr>SWxXinCxj3moEn5U/<wbr>K2gr6oXwibIcMz0A2<br>
fiiZzjqBO5YHUFymluICju6ZHer5oh<wbr>Go92gA6LI1AUUiVWKDqYD0IT4btciO<wbr>721h<br>
VWrrrCknaARtvU83yT9Vyc1I64iKMC<wbr>m5gShhHcb9MDJwYtHihXzyXuSWKZR7<wbr>g9wm<br>
w1EovmxiQJKIHgz1A0hBnlwwMyJczx<wbr>PEpxRfunHFuiT87TlMZPGJ1oFZhzBx<wbr>6K1L<br>
C9tmSkn2ycN8Ng+<wbr>pQO3fEdElxUoE0P13BR5mD2oby6V7M<wbr>npvEIc=<br>
=8fHr<br>
-----END PGP SIGNATURE-----<br>
<span class="HOEnZb"><font color="#888888">--<br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/<wbr>confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a></font></span></blockquote></div><br></div>