<div dir="ltr"><div dir="ltr"><br></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Fri, Jul 9, 2021 at 1:45 PM <<a href="mailto:vadud3@gmail.com">vadud3@gmail.com</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="ltr"><div dir="ltr"><br></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Fri, Jul 9, 2021 at 11:57 AM Peter Schober <<a href="mailto:peter.schober@univie.ac.at" target="_blank">peter.schober@univie.ac.at</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">* <a href="mailto:vadud3@gmail.com" target="_blank">vadud3@gmail.com</a> <<a href="mailto:vadud3@gmail.com" target="_blank">vadud3@gmail.com</a>> [2021-07-09 16:56]:<br>
> I compared the metadata of<br>
> <a href="https://server.example.org/Shibboleth.sso/Metadata" rel="noreferrer" target="_blank">https://server.example.org/Shibboleth.sso/Metadata</a> with<br>
> <a href="https://node1.example.org/Shibboleth.sso/Metadata" rel="noreferrer" target="_blank">https://node1.example.org/Shibboleth.sso/Metadata</a> and they both have the<br>
> same<br>
> entityID <a href="https://server.example.org" rel="noreferrer" target="_blank">https://server.example.org</a>.<br>
> <br>
> However, the Location for <a href="http://server.example.org" rel="noreferrer" target="_blank">server.example.org</a> is <a href="https://server.example.org" rel="noreferrer" target="_blank">https://server.example.org</a><br>
> and for <a href="http://node1.example.org" rel="noreferrer" target="_blank">node1.example.org</a> is <a href="https://node1.example.org" rel="noreferrer" target="_blank">https://node1.example.org</a><br>
> <br>
> Does that make sense of the same entityID for both? I can then send the<br>
> metadata from node1 to the IdP admin team.<br>
<br>
If you have decided that both servers/vhosts/whetever are in fact one<br>
thing (or rather, do not need to be told apart by any IDPs for local<br>
policy decisions) -- see item 3 from my earlier reply -- you can give<br>
them both the same entityID (and also key pair), no problem.<br>
<br>
But there the software on either server doesn't know that there's the<br>
other side so none of the tools on either side will give you the<br>
complete metadata automatically. I.e., you'd have to assemle the<br>
metadata to give to the IDP:<br>
* One entityID (same on both servers)<br>
* One keypair (same on both servers)<br>
* The relevant ACS URL (HTTP-POST at least) *for* *each* server/host,<br>
  with a unique index XML attribute (index="0" for one, index="1" for<br>
  the other, for example).<br>
<br>
I.e.:<br>
<br>
1. Make the key pair used for SAML the same on both servers.<br>
2. Generate metadata for one of the servers<br>
3. Amend that metadata by hand with the ACS URL for the other server/s<br>
4. Provide amended metadata to the IDP to use.<br>
<br></blockquote><div><br></div><div>EntityNaming under CONCEPTS space aligns with your suggestion of being a unique entity.</div><div>I will modify the enitityID for the node1 vhost and send it over to IDP. </div><div><br></div><div>Thanks a lot!</div><div>Asif</div><div><br></div><div><br></div><div> </div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
-peter<br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.ne</a>t</blockquote></div></div></blockquote><div><br></div>When I try to login to <a href="http://node1.server.com/" target="_blank">node1.server.com</a>, it redirects me to login page of <a href="http://server.example.com/" target="_blank">server.example.com</a>. Here are the steps. Not sure how to troubleshoot this.<div><br></div><div>I first try to login to node1 page</div><div><br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><a href="https://node1.example.org/jira" target="_blank">https://node1.example.org/jira</a></blockquote><div><br></div><div>It takes me to signon page</div><div><br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><a href="https://server.example.org/shibboleth-ds/index.html?entityID=https://node1.example.org&return=https://node1.example.org/Shibboleth.sso/Login?SAMLDS=1&target=ss:mem:f751c18ac676b4941f08555d8e5fbfcab3c36b9092417f1c8ffd29f3" target="_blank">https://server.example.org/shibboleth-ds/index.html?entityID=https://node1.example.org&return=https://node1.example.org/Shibboleth.sso/Login?SAMLDS=1&target=ss:mem:f751c18ac676b4941f08555d8e5fbfcab3c36b9092417f1c8ffd29f3</a></blockquote><div><br></div><div>I click on signon button which links to below</div><div><br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><a href="https://server.example.org/Shibboleth.sso/Login?SAMLDS=1&target=ss:mem:f751c18ac676b4941f08555d8e5fbfcab3c36b9092417f1c8ffd29f3&entityID=http://ssotest.example.org/adfs/services/trust" target="_blank">https://server.example.org/Shibboleth.sso/Login?SAMLDS=1&target=ss:mem:f751c18ac676b4941f08555d8e5fbfcab3c36b9092417f1c8ffd29f3&entityID=http://ssotest.example.org/adfs/services/trust</a></blockquote><div><br></div><div>On the chrome Network console I see the samlrequest</div><div><br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><a href="https://ssotest.example.org/adfs/ls/?SAMLRequest=....&RelayState=ss:mem:f751c18ac676b4941f08555d8e5fbfcab3c36b9092417f1c8ffd29f3&SigAlg=http://www.w3.org/2001/04/xmldsig-more#rsa-sha256&Signature=f3esrxiTFWYxo2KDSsNBdXAADsQ/YBhohzY8z6x3PTtETpc7gl0VviXNwAEpcLp7LitGfd82nqiNU32E/nUWVnO37fJGyuUFnaAIhQcXeGxI6nGTy+HWiCouuVDgdMXrzvf/M5K7rS3cw1tbOoGPAeiEUv8xh5aR1v6c0XjUTno9ZC2ERo7OtEhPA6F/sCdK4e0eGnx0RCop2PLdVdeprPk25gczGjBwhKxsx3wxFeqRU/OqMepmFLB3SBqXXRaEy1ekyE0Hqb9axYhdJqn85j9Dl3eOpkKwabZdjDF010GYy4p2vJo3qzu+RB+N8NL75XXbWn3Q==" target="_blank">https://ssotest.example.org/adfs/ls/?SAMLRequest=....&RelayState=ss:mem:f751c18ac676b4941f08555d8e5fbfcab3c36b9092417f1c8ffd29f3&SigAlg=http://www.w3.org/2001/04/xmldsig-more#rsa-sha256&Signature=f3esrxiTFWYxo2KDSsNBdXAADsQ/YBhohzY8z6x3PTtETpc7gl0VviXNwAEpcLp7LitGfd82nqiNU32E/nUWVnO37fJGyuUFnaAIhQcXeGxI6nGTy+HWiCouuVDgdMXrzvf/M5K7rS3cw1tbOoGPAeiEUv8xh5aR1v6c0XjUTno9ZC2ERo7OtEhPA6F/sCdK4e0eGnx0RCop2PLdVdeprPk25gczGjBwhKxsx3wxFeqRU/OqMepmFLB3SBqXXRaEy1ekyE0Hqb9axYhdJqn85j9Dl3eOpkKwabZdjDF010GYy4p2vJo3qzu+RB+N8NL75XXbWn3Q==</a></blockquote><div><br></div><div>SAMLRequest is</div><div><br></div><div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><samlp:AuthnRequest xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol"<br>AssertionConsumerServiceURL="<a href="https://server.example.org/Shibboleth.sso/SAML2/POST" target="_blank">https://server.example.org/Shibboleth.sso/SAML2/POST</a>"<br>Destination="<a href="https://ssotest.example.org/adfs/ls/" target="_blank">https://ssotest.example.org/adfs/ls/</a>"<br>ID="_dafedbb9424fd98c192d040ba9833"<br>IssueInstant="2021-07-14T14:11:00Z"<br>ProtocolBinding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Version="2.0"><br><saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"><br><a href="https://server.example.org/" target="_blank">https://server.example.org</a><br></saml:Issuer><br><samlp:NameIDPolicy AllowCreate="1"/></blockquote><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"></samlp:AuthnRequest></blockquote></div><div><br></div><div>Then takes me back to the login page of the server. So login to node1 never worked. The next three steps on Network console are</div><div><br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">GET <a href="https://ssotest.example.org/favicon.ico" target="_blank">https://ssotest.example.org/favicon.ico</a><br>POST <a href="https://server.example.org/Shibboleth.sso/SAML2/POST" target="_blank">https://server.example.org/Shibboleth.sso/SAML2/POST</a><br>GET <a href="https://server.example.org/" target="_blank">https://server.example.org/</a></blockquote><div><br></div><div>I am kind of lost. Any suggestion on what is going on and how to troubleshoot this?</div><div><br></div><div>Thanks,</div><div>Asif </div></div><br clear="all"><div><br></div>-- <br><div dir="ltr" class="gmail_signature">Asif Iqbal<br>PGP Key: 0xE62693C5 KeyServer: <a href="http://pgp.mit.edu" target="_blank">pgp.mit.edu</a><br>A: Because it messes up the order in which people normally read text.<br>Q: Why is top-posting such a bad thing?<br><br></div></div>