<div dir="auto">ACM certs are totally fine for TLS(be sure to use 1.2) but should be dedicated per target group/external facing DNS name. They should also be different from the SP's own encryption certificate(s). The certificates generated during Shibboleth installation should be fine for production use, but you can make your own if you'd prefer.<div dir="auto"><br></div><div dir="auto">The important thing is to keep data private by avoiding plain HTTP and wildcard certificates when possible and using encryption, as well as figuring out where the error is.</div><div dir="auto"><br></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Tue, Nov 26, 2019, 2:48 PM Deirdre Kirmis <<a href="mailto:Deirdre.Kirmis@asu.edu">Deirdre.Kirmis@asu.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div lang="EN-US" link="blue" vlink="purple">
<div class="m_4350979883552513183WordSection1">
<p class="MsoNormal">Thanks, Nate. You did suggest creating the SSL certs locally, which is what I will try next. I had already gotten so far with the ACM certs that I was trying to make that work first, but not really having luck. I’ll try your suggestions.<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">Deirdre Kirmis<u></u><u></u></p>
<p class="MsoNormal">Technology Services<u></u><u></u></p>
<p class="MsoNormal">Arizona State University Library<u></u><u></u></p>
<p class="MsoNormal">480-965-7240<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal"><b>From:</b> users <<a href="mailto:users-bounces@shibboleth.net" target="_blank" rel="noreferrer">users-bounces@shibboleth.net</a>> <b>On Behalf Of
</b>Nate Klingenstein<br>
<b>Sent:</b> Tuesday, November 26, 2019 2:41 PM<br>
<b>To:</b> Shib Users <<a href="mailto:users@shibboleth.net" target="_blank" rel="noreferrer">users@shibboleth.net</a>><br>
<b>Subject:</b> Re: configuring shibboleth on AWS using ELB<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<div>
<p class="MsoNormal">Deirdre,<u></u><u></u></p>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">Beware the wildcard certificate, especially as ACM is effectively free and zero maintenance. The domain in the cookie and the certificate used for encryption to the SP are more important, but it's wise to use dedicated TLS certificates
anyway.<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">I wouldn't have ELB listen on port 80, but instead write a redirect rule.<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">The error doesn't sound like a Shibboleth error. Try going to /Shibboleth.sso/Session. I suspect it's not integrated right with the application or not receiving the right data in the assertion even though the SAML transaction is probably
successful.<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">Best wishes,<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal">Nate.<u></u><u></u></p>
</div>
<p class="MsoNormal" style="margin-bottom:12.0pt"><u></u> <u></u></p>
<div>
<div>
<p class="MsoNormal">On Tue, Nov 26, 2019, 2:31 PM Deirdre Kirmis <<a href="mailto:Deirdre.Kirmis@asu.edu" target="_blank" rel="noreferrer">Deirdre.Kirmis@asu.edu</a>> wrote:<u></u><u></u></p>
</div>
<blockquote style="border:none;border-left:solid #cccccc 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in">
<div>
<div>
<p class="MsoNormal">I figured out the certs issue…do you mind if I ask if I have set this up correctly? I have an application load balancer, listening on ports 80 and 443, directing to a target group
(with currently only 1 EC2 instance registered). I set up the ELB using our AWS wildcard certificate in ACM, and did not configure anything specifically on the EC2 to enforce https and regarding certs (ssl.conf is pointing to the localhost.key and .crt files).
I guess the “wired together properly” part is where I’m stuck. I installed shib, added the Location section for it in ssl.conf, configured shibboleth2.xml with servername and to point to my metadata file, which I got from my host provider (my organization
is an IDP). Added shib as an authentication provider. <u></u><u></u></p>
<p class="MsoNormal"> <u></u><u></u></p>
<p class="MsoNormal">I see my provider on the login page of my app, but when I try to login I get an error “The login service was unable to identify a compatible way to respond to the requested application.
This is generally due to a misconfiguration on the part of the application and should be reported to the application's support team or owner.”<u></u><u></u></p>
<p class="MsoNormal"> <u></u><u></u></p>
<p class="MsoNormal">Any ideas what I missed? Thank you!<u></u><u></u></p>
<p class="MsoNormal"> <u></u><u></u></p>
<div>
<p class="MsoNormal">Deirdre Kirmis<u></u><u></u></p>
<p class="MsoNormal">Technology Services<u></u><u></u></p>
<p class="MsoNormal">Arizona State University Library<u></u><u></u></p>
<p class="MsoNormal">480-965-7240<u></u><u></u></p>
</div>
<p class="MsoNormal"> <u></u><u></u></p>
<div>
<div style="border:none;border-top:solid #e1e1e1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b>From:</b> users <<a href="mailto:users-bounces@shibboleth.net" target="_blank" rel="noreferrer">users-bounces@shibboleth.net</a>>
<b>On Behalf Of </b>Nate Klingenstein<br>
<b>Sent:</b> Monday, November 25, 2019 5:54 PM<br>
<b>To:</b> Shib Users <<a href="mailto:users@shibboleth.net" target="_blank" rel="noreferrer">users@shibboleth.net</a>><br>
<b>Subject:</b> RE: configuring shibboleth on AWS using ELB<u></u><u></u></p>
</div>
</div>
<p class="MsoNormal"> <u></u><u></u></p>
<p style="margin:0in;margin-bottom:.0001pt"><span style="font-size:12.0pt;font-family:"Arial",sans-serif">Deirdre,</span><u></u><u></u></p>
<p style="margin:0in;margin-bottom:.0001pt"><span style="font-size:12.0pt;font-family:"Arial",sans-serif"> </span><u></u><u></u></p>
<p style="margin:0in;margin-bottom:.0001pt"><span style="font-size:12.0pt;font-family:"Arial",sans-serif">For what it's worth, we've configured a lot of IdP's and SP's in AWS, including SAMLtest. It's pretty straightforward: ELB, target groups, and instances,
just wired together properly. There's really nothing special about it.</span><u></u><u></u></p>
<p style="margin:0in;margin-bottom:.0001pt"><span style="font-size:12.0pt;font-family:"Arial",sans-serif"> </span><u></u><u></u></p>
<p style="margin:0in;margin-bottom:.0001pt"><span style="font-size:12.0pt;font-family:"Arial",sans-serif">I often do it for single instances just because I like having ELB in between the world and me. It doesn't really provide anything that security groups
wouldn't other than IP address obfuscation, so it's more of a security blanket than a necessary piece of infrastructure, but hey.</span><u></u><u></u></p>
<p style="margin:0in;margin-bottom:.0001pt"><span style="font-size:12.0pt;font-family:"Arial",sans-serif"> </span><u></u><u></u></p>
<p style="margin:0in;margin-bottom:.0001pt"><span style="font-size:12.0pt;font-family:"Arial",sans-serif">Take care,</span><u></u><u></u></p>
<p style="margin:0in;margin-bottom:.0001pt"><span style="font-size:12.0pt;font-family:"Arial",sans-serif">Nate.</span><u></u><u></u></p>
<p style="margin:0in;margin-bottom:.0001pt"><span style="font-size:12.0pt;font-family:"Arial",sans-serif"> </span><u></u><u></u></p>
<p style="margin:0in;margin-bottom:.0001pt"><span style="font-size:12.0pt;font-family:"Arial",sans-serif">--------</span><u></u><u></u></p>
<p style="margin:0in;margin-bottom:.0001pt"><span style="font-size:12.0pt;font-family:"Arial",sans-serif"> </span><u></u><u></u></p>
<p style="margin:0in;margin-bottom:.0001pt"><span style="font-size:12.0pt;font-family:"Arial",sans-serif;border:solid windowtext 1.0pt;padding:0in"><img border="0" width="100" height="100" style="width:1.0416in;height:1.0416in" id="m_4350979883552513183m_-1198035815259949932_x005f_x0000_i1025" src="cid:image001.jpg@01D5A468.78C8FE90" alt="Image removed by sender."></span><u></u><u></u></p>
<p style="margin:0in;margin-bottom:.0001pt"><span style="font-size:13.5pt;font-family:"Arial",sans-serif">The Art of Access</span><span style="font-size:12.0pt;font-family:"Arial",sans-serif">
<strong><span style="font-family:"Arial",sans-serif">®</span></strong></span><u></u><u></u></p>
<p style="margin:0in;margin-bottom:.0001pt"><span style="font-size:12.0pt;font-family:"Arial",sans-serif"> </span><u></u><u></u></p>
<p style="margin:0in;margin-bottom:.0001pt"><strong><span style="font-size:10.0pt;font-family:"Arial",sans-serif">Nate Klingenstein</span></strong><span style="font-size:10.0pt;font-family:"Arial",sans-serif"> | Principal</span><u></u><u></u></p>
<p style="margin:0in;margin-bottom:.0001pt"><span style="font-size:10.0pt;font-family:"Arial",sans-serif"><a href="https://urldefense.proofpoint.com/v2/url?u=https-3A__www.signet.id_&d=DwMFaQ&c=l45AxH-kUV29SRQusp9vYR0n1GycN4_2jInuKy6zbqQ&r=X1YAM2yWs1HIcWRXyPCSUtCKxhQO748y834uz5ZFnTY&m=DKyXVdvZv_W0BxCMlPe5V6NyJWWVhQZynmMLKEIxOg4&s=PIehe9gqAJbDbVJPUhq8JhjM-UPEkeVHjaz6e2VSOhs&e=" target="_blank" rel="noreferrer">https://www.signet.id/</a>
</span><u></u><u></u></p>
<p style="margin:0in;margin-bottom:.0001pt"><span style="font-size:12.0pt;font-family:"Arial",sans-serif"> </span><u></u><u></u></p>
<blockquote style="border:none;border-left:solid #b0b0b7 1.5pt;padding:0in 0in 0in 4.0pt;margin-left:3.75pt;margin-top:5.0pt;margin-right:0in;margin-bottom:5.0pt">
<p class="MsoNormal" style="margin-bottom:12.0pt">-----Original message-----<br>
<strong><span style="font-family:"Calibri",sans-serif">From:</span></strong> Deirdre Kirmis<br>
<strong><span style="font-family:"Calibri",sans-serif">Sent:</span></strong> Monday, November 25 2019, 4:30 pm<br>
<strong><span style="font-family:"Calibri",sans-serif">To:</span></strong> <a href="mailto:users@shibboleth.net" target="_blank" rel="noreferrer">
users@shibboleth.net</a><br>
<strong><span style="font-family:"Calibri",sans-serif">Subject:</span></strong> configuring shibboleth on AWS using ELB<br>
<br>
<u></u><u></u></p>
<div>
<p class="MsoNormal">Hi all…prefacing this to say that I am new to AWS and new to configuring shibboleth. I was wondering if anyone has successfully configured shibboleth on an AWS instance that is
running https via a load balancer. I installed and configured shib, send/received metadata from my IDP, but when I generate my metadata file, the certs are not included, and the sp-cert.pem and sp-key.pem files did not get created. Do I still need to “configure”
https locally on the server, and if so, how, and how do I fix my shib config?<u></u><u></u></p>
<p class="MsoNormal"> <u></u><u></u></p>
<p class="MsoNormal">Thanks for any help!<u></u><u></u></p>
<p class="MsoNormal"> <u></u><u></u></p>
</div>
<pre>-- <u></u><u></u></pre>
<pre> <u></u><u></u></pre>
<pre>For Consortium Member technical support, see <a href="https://urldefense.proofpoint.com/v2/url?u=https-3A__wiki.shibboleth.net_confluence_x_coFAAg&d=DwMFaQ&c=l45AxH-kUV29SRQusp9vYR0n1GycN4_2jInuKy6zbqQ&r=X1YAM2yWs1HIcWRXyPCSUtCKxhQO748y834uz5ZFnTY&m=sqANvdo-pk4xMc-5_iT2zb4zkizPauGoywFExzSpVTM&s=kIf-cAbo_9TAnkon9__fNxvH0qm7mV0Y4cv_LoMrPJU&e=" target="_blank" rel="noreferrer">https://wiki.shibboleth.net/confluence/x/coFAAg</a><u></u><u></u></pre>
<pre> <u></u><u></u></pre>
<pre>To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank" rel="noreferrer">users-unsubscribe@shibboleth.net</a><u></u><u></u></pre>
</blockquote>
</div>
</div>
<p class="MsoNormal">-- <br>
For Consortium Member technical support, see <a href="https://urldefense.proofpoint.com/v2/url?u=https-3A__wiki.shibboleth.net_confluence_x_coFAAg&d=DwMFaQ&c=l45AxH-kUV29SRQusp9vYR0n1GycN4_2jInuKy6zbqQ&r=X1YAM2yWs1HIcWRXyPCSUtCKxhQO748y834uz5ZFnTY&m=sqANvdo-pk4xMc-5_iT2zb4zkizPauGoywFExzSpVTM&s=kIf-cAbo_9TAnkon9__fNxvH0qm7mV0Y4cv_LoMrPJU&e=" target="_blank" rel="noreferrer">
https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank" rel="noreferrer">
users-unsubscribe@shibboleth.net</a><u></u><u></u></p>
</blockquote>
</div>
</div>
</div>
</div>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank" rel="noreferrer">users-unsubscribe@shibboleth.net</a></blockquote></div>