<html xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Aptos;
        panose-1:2 11 0 4 2 2 2 2 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        font-size:10.0pt;
        font-family:"Aptos",sans-serif;}
span.EmailStyle19
        {mso-style-type:personal-reply;
        font-family:"Aptos",sans-serif;
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;
        mso-ligatures:none;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style>
</head>
<body lang="EN-US" link="#467886" vlink="#96607D" style="word-wrap:break-word">
<div class="WordSection1">
<p class="MsoNormal"><span style="font-size:11.0pt">Hi Scott,<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">We don’t have a web.xml file at all.  I deleted it since the docs seemed to indicate it was no longer needed and could cause issues.  I have tried using the web.xml from the dist directory also, but that made
 no difference.  I’m currently running with no web.xml again (and have rebuilt the war file).<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">There is also no remoteuser-authn-config.xml file currently, since that also has been documented as unnecessary.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">We used to have code in general-authn.xml defining an authn/RemoteUser bean, but that has been commented out.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">Our configuration has been upgraded since at least IdP v3, so it’s more complex than a vanilla install, but I think the above steps should have removed any interfering RemoteUser config.  In addition, I no
 longer see the “Replacing auto-wired component: authn/RemoteUser” in the log, which should imply that we are using the auto-wired version.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">Are there any positive steps we need to take when switching over to the auto-wired configuration?  When the upgrade was performed, the above steps hadn’t been taken yet, and I don’t know if we’re missing something
 that activates the newer default RemoteUser.  Other beans are still coming from the old style config files, and I’m not sure if something could interfere with the RemoteUser configuration that way.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">Ahhh crud.  I think I just found the problem.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">Our upgraded configuration did not define idp.searchForProperties, so they were not automatically sought out.  And I had not added the /conf/authn/authn.properties to the list of idp.additionalProperties. 
 Argh.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">After adding that file to the list of additional properties, the certificate-based login is working now.  Imagine that.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">Alright, I think this issue is solved, and embarrassingly enough, it was totally simple.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">Thanks for your assistance in helping me track down the problem.  Not sure if anyone else would trip up this way, but at least now there’s a thread about it.  Dang.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">Thanks,<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">Chris<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif">-- <o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif">Chris Koeritz<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif">Senior Linux and Storage Engineer <o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif">University of Virginia ITS - Backup, Storage, and Archive Services<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif">P: 434 982 4690<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
<div id="mail-editor-reference-message-container">
<div>
<div style="border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal" style="margin-bottom:12.0pt"><b><span style="font-size:12.0pt;color:black">From:
</span></b><span style="font-size:12.0pt;color:black">Cantor, Scott <cantor.2@osu.edu><br>
<b>Date: </b>Tuesday, July 23, 2024 at 10:53</span><span style="font-size:12.0pt;font-family:"Arial",sans-serif;color:black"> </span><span style="font-size:12.0pt;color:black">AM<br>
<b>To: </b>Shib Users <users@shibboleth.net><br>
<b>Cc: </b>Koeritz, Chris (cak0l) <cak0l@virginia.edu><br>
<b>Subject: </b>Re: Question about Shibboleth IdP v5 with Jetty 12 and extra RemoteUser headers for TLS termination by F5<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="margin-bottom:12.0pt"><span style="font-size:11.0pt">> Does anything come to mind about why the RemoteUser<br>
> servlet isn’t scooping that up? <br>
<br>
Yes, your configuration isn't what you think it is. The snippet you posted shows the right property set,  but it's simply not. Cranking up logging will log all the properties set during startup, generally in the container log, and should also warn about duplicates.<br>
<br>
Also see if there's content in web.xml from the old days configuring the servlet that might be interfering with the use of a property.<br>
<br>
-- Scott<br>
<br>
<o:p></o:p></span></p>
</div>
</div>
</div>
</div>
</body>
</html>