<html xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=Windows-1252">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:Courier;
        panose-1:2 0 5 0 0 0 0 0 0 0;}
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:"Helvetica Neue";
        panose-1:2 0 5 3 0 0 0 2 0 4;}
@font-face
        {font-family:Menlo;
        panose-1:2 11 6 9 3 8 4 2 2 4;}
@font-face
        {font-family:Tahoma;
        panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
p.p1, li.p1, div.p1
        {mso-style-name:p1;
        margin:0in;
        font-size:10.5pt;
        font-family:"Helvetica Neue";
        color:black;}
p.p2, li.p2, div.p2
        {mso-style-name:p2;
        margin:0in;
        font-size:8.5pt;
        font-family:Menlo;
        color:black;}
p.p3, li.p3, div.p3
        {mso-style-name:p3;
        margin:0in;
        font-size:10.5pt;
        font-family:"Helvetica Neue";
        color:black;}
p.p4, li.p4, div.p4
        {mso-style-name:p4;
        margin:0in;
        background:white;
        font-size:8.5pt;
        font-family:"Helvetica Neue";
        color:#121F3C;}
p.p5, li.p5, div.p5
        {mso-style-name:p5;
        margin:0in;
        font-size:8.5pt;
        font-family:"Helvetica Neue";
        color:#121F3C;}
p.p6, li.p6, div.p6
        {mso-style-name:p6;
        margin:0in;
        font-size:9.0pt;
        font-family:"Helvetica Neue";
        color:black;}
p.p7, li.p7, div.p7
        {mso-style-name:p7;
        margin:0in;
        font-size:9.0pt;
        font-family:"Helvetica Neue";
        color:black;}
p.p8, li.p8, div.p8
        {mso-style-name:p8;
        margin:0in;
        font-size:8.5pt;
        font-family:"Helvetica Neue";}
p.p9, li.p9, div.p9
        {mso-style-name:p9;
        margin:0in;
        font-size:10.5pt;
        font-family:"Helvetica Neue";
        color:#FC1427;}
p.p10, li.p10, div.p10
        {mso-style-name:p10;
        margin:0in;
        font-size:9.0pt;
        font-family:"Helvetica Neue";
        color:black;}
p.p11, li.p11, div.p11
        {mso-style-name:p11;
        margin:0in;
        font-size:10.5pt;
        font-family:"Helvetica Neue";
        color:black;}
p.p12, li.p12, div.p12
        {mso-style-name:p12;
        margin:0in;
        background:white;
        font-size:9.0pt;
        font-family:"Helvetica Neue";
        color:#121F3C;}
p.p13, li.p13, div.p13
        {mso-style-name:p13;
        margin:0in;
        font-size:9.0pt;
        font-family:"Helvetica Neue";
        color:black;}
p.p14, li.p14, div.p14
        {mso-style-name:p14;
        margin:0in;
        font-size:12.0pt;
        font-family:"Helvetica Neue";
        color:#121F3C;}
p.p15, li.p15, div.p15
        {mso-style-name:p15;
        margin:0in;
        font-size:9.0pt;
        font-family:"Helvetica Neue";
        color:black;}
p.p16, li.p16, div.p16
        {mso-style-name:p16;
        margin:0in;
        font-size:9.0pt;
        font-family:"Helvetica Neue";
        color:black;}
p.p17, li.p17, div.p17
        {mso-style-name:p17;
        margin:0in;
        background:white;
        font-size:7.5pt;
        font-family:"Helvetica Neue";
        color:#121F3C;}
p.p18, li.p18, div.p18
        {mso-style-name:p18;
        margin:0in;
        font-size:10.5pt;
        font-family:"Helvetica Neue";
        color:#FC1427;}
p.p19, li.p19, div.p19
        {mso-style-name:p19;
        margin:0in;
        font-size:10.5pt;
        font-family:"Helvetica Neue";
        color:black;}
p.p20, li.p20, div.p20
        {mso-style-name:p20;
        margin:0in;
        font-size:10.5pt;
        font-family:"Helvetica Neue";
        color:black;}
p.p21, li.p21, div.p21
        {mso-style-name:p21;
        margin:0in;
        background:white;
        font-size:12.0pt;
        font-family:"Helvetica Neue";
        color:#121F3C;}
p.p22, li.p22, div.p22
        {mso-style-name:p22;
        margin:0in;
        font-size:7.5pt;
        font-family:"Helvetica Neue";
        color:#121F3C;}
p.p23, li.p23, div.p23
        {mso-style-name:p23;
        margin:0in;
        font-size:4.5pt;
        font-family:"Helvetica Neue";
        color:black;}
p.p24, li.p24, div.p24
        {mso-style-name:p24;
        margin:0in;
        font-size:8.5pt;
        font-family:"Tahoma",sans-serif;}
p.p25, li.p25, div.p25
        {mso-style-name:p25;
        margin:0in;
        font-size:10.5pt;
        font-family:"Helvetica Neue";
        color:black;}
p.p26, li.p26, div.p26
        {mso-style-name:p26;
        margin:0in;
        background:white;
        font-size:7.5pt;
        font-family:"Helvetica Neue";
        color:#121F3C;}
p.p27, li.p27, div.p27
        {mso-style-name:p27;
        margin:0in;
        font-size:7.5pt;
        font-family:"Helvetica Neue";
        color:#121F3C;}
p.p28, li.p28, div.p28
        {mso-style-name:p28;
        margin:0in;
        font-size:10.0pt;
        font-family:Courier;
        color:#090909;}
p.p29, li.p29, div.p29
        {mso-style-name:p29;
        margin:0in;
        font-size:8.5pt;
        font-family:"Helvetica Neue";
        color:#121F3C;}
p.p30, li.p30, div.p30
        {mso-style-name:p30;
        margin:0in;
        font-size:10.0pt;
        font-family:Courier;
        color:#090909;}
p.p31, li.p31, div.p31
        {mso-style-name:p31;
        margin:0in;
        font-size:8.0pt;
        font-family:"Tahoma",sans-serif;}
span.s3
        {mso-style-name:s3;
        background:white;}
span.s4
        {mso-style-name:s4;
        font-family:"Helvetica Neue";
        background:white;}
span.s5
        {mso-style-name:s5;
        font-family:"Helvetica Neue";
        color:black;}
span.s6
        {mso-style-name:s6;
        font-family:"Helvetica Neue";
        color:#FC1427;}
span.s7
        {mso-style-name:s7;
        font-family:"Helvetica Neue";
        color:#FC1427;}
span.apple-converted-space
        {mso-style-name:apple-converted-space;}
span.s1
        {mso-style-name:s1;}
span.s2
        {mso-style-name:s2;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style>
</head>
<body lang="EN-US" link="blue" vlink="purple" style="word-wrap:break-word">
<div class="WordSection1">
<p class="p1">(Still thankful for help I got in this forum back in March, with setting up my EDS!)<o:p></o:p></p>
<p class="p1"> <o:p></o:p></p>
<p class="p1">As my Plan A, I am trying to get my IdP, after authentication, to call my own …/rest/consume, instead of the Shibboleth.sso/SAML2/POST that it is going to now.<o:p></o:p></p>
<p class="p1">As a Plan B, less desirable, I would try to adjust the target URL that it returns to after authentication and SAML2/POST to be my static value.<o:p></o:p></p>
<p class="p1"> <o:p></o:p></p>
<p class="p1">I tried (1)-(4) below, hoping for success in either Plan A or B. (1) and (2) seem to have no effect. (3) and (4) fail, and the error messages lead me to think that they may not be (directly) addressing either of my goals. FWIW, the errors also
 indicate that Shibboleth pays attention only to my host-and-port, not the whole path in the URL.<o:p></o:p></p>
<p class="p1"> <o:p></o:p></p>
<p class="p1">For experimental clarity in the error messages, I used different ports for each of the 4 cases. And of course my ‘final’ version would probably not be saying 127.0.0.1<o:p></o:p></p>
<p class="p1"> <o:p></o:p></p>
<p class="p1">Any guidance / help to get either my ACS URL (AssertionConsumerServiceURL) to go to my /consume, or to get the post-authentication target page to go there?<o:p></o:p></p>
<p class="p1"> <o:p></o:p></p>
<p class="p1">Thanks, - Carl<o:p></o:p></p>
<p class="p1">-----------------------------------------------------------------------------------------------------------------<o:p></o:p></p>
<p class="p1"><b> </b><o:p></o:p></p>
<p class="p1"><b>(0) Using SHIBD 3:<span class="apple-converted-space"> </span></b><o:p></o:p></p>
<p class="p2"><span class="s1">[root@shrine-sso-node01 conf.d]# shibd -v</span><o:p></o:p></p>
<p class="p2"><span class="s1">shibboleth 3.3.0</span><o:p></o:p></p>
<p class="p3"> <o:p></o:p></p>
<p class="p1"><b>(1) Try to Intercept saml2/post in sp.conf</b><o:p></o:p></p>
<p class="p4"><span class="s2"><LocationMatch "/Shibboleth.sso/SAML2/POST"></span><o:p></o:p></p>
<p class="p4"><span class="apple-converted-space">    </span><span class="s2">RewriteRule .* http://127.0.0.1:8081/shrine-api/sso/rest/consume [R]</span><o:p></o:p></p>
<p class="p5"><span class="s3"></LocationMatch></span><o:p></o:p></p>
<p class="p6"> <o:p></o:p></p>
<p class="p7">See: https://shibboleth.atlassian.net/wiki/spaces/IDP30/pages/2496561158/Troubleshooting#Troubleshooting-Theloginservicewasunabletoidentifyacompatiblewaytorespondtotherequestedapplication...<o:p></o:p></p>
<p class="p8"><span class="s3"><span style="color:black">The value of the URL in a Shibboleth SP is determined by the computed request URL that led to the issuance of the request and is primarily a function of
<b>web server configuration (on Apache)</b></span></span><o:p></o:p></p>
<p class="p8"><span class="s3"><b><span style="color:black">(my emphasis added)</span></b></span><o:p></o:p></p>
<p class="p8"> <o:p></o:p></p>
<p class="p9"><b>Apparently a no-op. No effect (Sending that location  via ProxyPass* to …./consume also has no effect)</b><o:p></o:p></p>
<p class="p10"> <o:p></o:p></p>
<p class="p11"><b>(2) Set override-target in sp.conf</b><o:p></o:p></p>
<p class="p12"><span class="s2">ShibRequestSetting target http://127.0.0.1:8082/shrine-api/sso/rest/consume</span><o:p></o:p></p>
<p class="p10"> <o:p></o:p></p>
<p class="p13">See: https://shibboleth.atlassian.net/wiki/spaces/SP3/pages/2065335062/Apache#Properly-Routing-Handler-URLs<o:p></o:p></p>
<p class="p14"><span class="s4"><b><span style="font-size:10.5pt">AuthConfig Options</span></b></span><span class="s5"><span style="font-size:9.0pt"> /
</span></span><span class="s3">ShibRequestSetting setting value</span><o:p></o:p></p>
<p class="p15"> <o:p></o:p></p>
<p class="p16">which uses<o:p></o:p></p>
<p class="p16">https://shibboleth.atlassian.net/wiki/spaces/SP3/pages/2065334723/ContentSettings<o:p></o:p></p>
<p class="p14"><span class="s5"><span style="font-size:9.0pt">See: </span></span><span class="s3">target</span><span class="apple-converted-space"> </span><o:p></o:p></p>
<p class="p17"><span class="s2">Allows the resources to return to after SSO to be "locked" to a specific value, even when running as a result of active protection of other resources. In other words, this value overrides the actual resource location when SSO
 redirection is automatic, including initial access and after a timeout.</span><o:p></o:p></p>
<p class="p18"><b>Apparently a no-op — no error (see (3) and (4) below) and no effect</b><o:p></o:p></p>
<p class="p15"> <o:p></o:p></p>
<p class="p19"><b>(3) Try to intercept in RequestMap in shibboleth2.xml</b><o:p></o:p></p>
<p class="p17"><span class="s2"><RequestMapper type="Native"></span><o:p></o:p></p>
<p class="p17"><span class="apple-converted-space">    </span><span class="s2"><RequestMap target="http://127.0.0.1:8083/shrine-api/sso/rest/consume"></span><o:p></o:p></p>
<p class="p17"><span class="apple-converted-space">    </span><span class="s2"></RequestMap></span><o:p></o:p></p>
<p class="p17"><span class="s2"></RequestMapper></span><o:p></o:p></p>
<p class="p20"> <o:p></o:p></p>
<p class="p16">See: https://shibboleth.atlassian.net/wiki/spaces/SP3/pages/2065334885/RequestMap<o:p></o:p></p>
<p class="p21"><span class="s2">target</span><o:p></o:p></p>
<p class="p22"><span class="s3">Allows the resources to return to after SSO to be "locked" to a specific value, even when running as a result of active protection of other resources. In other words, this value overrides the actual resource location when SSO
 redirection is automatic, including initial access and after a timeout.</span><o:p></o:p></p>
<p class="p23"> <o:p></o:p></p>
<p class="p24"><span class="s6"><b><span style="font-size:10.5pt">Oops, results in</span></b></span><span class="s7"><span style="font-size:4.5pt">
</span></span><span class="s3"><span style="color:black">Error details: MSIS3200: No AssertionConsumerService is configured on the relying party trust…that is a prefix match of the AssertionConsumerService URL '<b>https://127.0.0.1:8083/Shibboleth.sso</b>/SAML2/POST'</span></span><o:p></o:p></p>
<p class="p25"> <o:p></o:p></p>
<p class="p11"><b>(4) Try to intercept in <SSO> in shibboleth2.xml</b><o:p></o:p></p>
<p class="p26"><span class="s2"><SSO entityID="http://sso.med.harvard.edu/adfs/services/trust"</span><o:p></o:p></p>
<p class="p26"><span class="apple-converted-space">     </span><span class="s2">target="http://127.0.0.1:8084/shrine-api/sso/rest/consume"></span><span class="apple-converted-space"> </span><o:p></o:p></p>
<p class="p26"><span class="apple-converted-space">    </span><span class="s2">SAML2</span><o:p></o:p></p>
<p class="p27"><span class="s3"></SSO></span><o:p></o:p></p>
<p class="p28"> <o:p></o:p></p>
<p class="p13">See: https://shibboleth.atlassian.net/wiki/spaces/SP3/pages/2065334348/SSO<o:p></o:p></p>
<p class="p21"><span class="s2">target</span><o:p></o:p></p>
<p class="p29"><span class="s3">Allows the resources to return to after SSO to be "locked" to a specific value, even when running as a result of active protection of other resources. In other words, this value overrides the actual resource location when SSO
 redirection is automatic, including initial access and after a timeout.</span><o:p></o:p></p>
<p class="p30"> <o:p></o:p></p>
<p class="p31"><span class="s6"><b><span style="font-size:10.5pt">Oops, results in</span></b></span><span class="s7"><span style="font-size:4.5pt">
</span></span><span class="s3"><span style="color:black">Error details: MSIS3200: No AssertionConsumerService is configured on the relying party trust 'https://shrine-sso-node01.catalyst.harvard.edu' that is a prefix match of the AssertionConsumerService URL
 '<b>https://127.0.0.1:8084/Shibboleth.sso</b>/SAML2/POST'</span></span><o:p></o:p></p>
<p class="p28"> <o:p></o:p></p>
<p class="p28"> <o:p></o:p></p>
<p class="p25"> <o:p></o:p></p>
<p class="MsoNormal"> <o:p></o:p></p>
</div>
</body>
</html>