<!DOCTYPE HTML><html>
<head>
<meta name="Generator" content="Amazon WorkMail v3.0-4526">
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<title>RE: configuring shibboleth on AWS using ELB</title>
</head>
<body>
<p style="margin: 0px; font-family: Arial, Tahoma, Helvetica, sans-serif; font-size: small;">Deirdre,</p><p style="margin: 0px; font-family: Arial, Tahoma, Helvetica, sans-serif; font-size: small;"> </p><p style="margin: 0px; font-family: Arial, Tahoma, Helvetica, sans-serif; font-size: small;">For what it's worth, we've configured a lot of IdP's and SP's in AWS, including SAMLtest.  It's pretty straightforward: ELB, target groups, and instances, just wired together properly.  There's really nothing special about it.</p><p style="margin: 0px; font-family: Arial, Tahoma, Helvetica, sans-serif; font-size: small;"> </p><p style="margin: 0px; font-family: Arial, Tahoma, Helvetica, sans-serif; font-size: small;">I often do it for single instances just because I like having ELB in between the world and me.  It doesn't really provide anything that security groups wouldn't other than IP address obfuscation, so it's more of a security blanket than a necessary piece of infrastructure, but hey.</p><p style="margin: 0px; font-family: Arial, Tahoma, Helvetica, sans-serif; font-size: small;"> </p><p style="margin: 0px; font-family: Arial, Tahoma, Helvetica, sans-serif; font-size: small;">Take care,</p><p style="margin: 0px; font-family: Arial, Tahoma, Helvetica, sans-serif; font-size: small;">Nate.</p><p style="font-family:Arial,Tahoma,Helvetica,sans-serif; font-size:small; margin:0px"> </p><p style="font-family:Arial,Tahoma,Helvetica,sans-serif; font-size:small; margin:0px">--------</p><p style="font-family:Arial,Tahoma,Helvetica,sans-serif; font-size:small; margin:0px"> </p><p style="font-family:Arial,Tahoma,Helvetica,sans-serif; font-size:small; margin:0px"><img src="https://www.signet.id/wp-content/uploads/2019/08/signature-e1566142203123.png" /></p><p style="font-family:Arial,Tahoma,Helvetica,sans-serif; font-size:small; margin:0px"><font size="4">The Art of Access</font> <strong>®</strong></p><p style="font-family:Arial,Tahoma,Helvetica,sans-serif; font-size:small; margin:0px"> </p><p style="font-family:Arial,Tahoma,Helvetica,sans-serif; font-size:small; margin:0px"><font size="2"><strong>Nate Klingenstein</strong> | Principal</font></p><p style="font-family:Arial,Tahoma,Helvetica,sans-serif; font-size:small; margin:0px"><font size="2"><a href="https://www.signet.id/">https://www.signet.id/</a> </font></p><p style="font-family:Arial,Tahoma,Helvetica,sans-serif; font-size:small; margin:0px"> </p><blockquote style="border-left:2px solid #b0b0b7; margin-left:5px; margin-right:0px; padding-left:5px">-----Original message-----<br /><strong>From:</strong> Deirdre Kirmis<br /><strong>Sent:</strong> Monday, November 25 2019, 4:30 pm<br /><strong>To:</strong> users@shibboleth.net<br /><strong>Subject:</strong> configuring shibboleth on AWS using ELB<br /><br /><!-- begin sanitized html --><style type="text/css"><--

@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}

p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:#0563C1;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:#954F72;
        text-decoration:underline;}
span.EmailStyle17
        {mso-style-type:personal-compose;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-family:"Calibri",sans-serif;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><div class="bodyclass"><div class="WordSection1"><p class="MsoNormal">Hi all…prefacing this to say that I am new to AWS and new to configuring shibboleth. I was wondering if anyone has successfully configured shibboleth on an AWS instance that is running https via a load balancer. I installed and configured shib, send/received metadata from my IDP, but when I generate my metadata file, the certs are not included, and the sp-cert.pem and sp-key.pem files did not get created. Do I still need to “configure” https locally on the server, and if so, how, and how do I fix my shib config?</p><p class="MsoNormal"> </p><p class="MsoNormal">Thanks for any help!</p><p class="MsoNormal"> </p></div></div><pre>-- 

For Consortium Member technical support, see https://wiki.shibboleth.net/confluence/x/coFAAg

To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net</pre> <!-- end sanitized html --></blockquote>
</body>
</html>