This shows you the differences between two versions of the page.
| Both sides previous revision Previous revision Next revision | Previous revision | ||
|
docpublic:systemes:shibboleth:idpv3x [2019/01/02 14:25] procacci@tem-tsp.eu [install] |
docpublic:systemes:shibboleth:idpv3x [2019/01/02 21:57] (current) procacci@tem-tsp.eu [SSO CAS] |
||
|---|---|---|---|
| Line 240: | Line 240: | ||
| Total time: 2 minutes 14 seconds | Total time: 2 minutes 14 seconds | ||
| - | </ | ||
| - | |||
| - | |||
| - | |||
| - | [root@idp3 shibboleth-identity-provider-3.2.1]# | ||
| - | [root@idp3 shibboleth-identity-provider-3.2.1]# | ||
| - | Source (Distribution) Directory: [/ | ||
| - | |||
| - | Installation Directory: [/ | ||
| - | |||
| - | Hostname: [localhost.localdomain] | ||
| - | idp3.tem-tsp.eu | ||
| - | SAML EntityID: [https:// | ||
| - | |||
| - | Attribute Scope: [localdomain] | ||
| - | tem-tsp.eu | ||
| - | Backchannel PKCS12 Password: glsecretidp | ||
| - | Re-enter password: | ||
| - | Cookie Encryption Key Password: | ||
| - | Password cannot be zero length | ||
| - | Cookie Encryption Key Password: glsecretidp | ||
| - | Re-enter password: | ||
| - | Warning: / | ||
| - | Warning: / | ||
| - | Warning: / | ||
| - | Warning: / | ||
| - | Warning: / | ||
| - | Generating Signing Key, CN = idpmt3.tem-tsp.eu URI = https:// | ||
| - | ...done | ||
| - | Creating Encryption Key, CN = idpmt3.tem-tsp.eu URI = https:// | ||
| - | ...done | ||
| - | Creating Backchannel keystore, CN = idpmt3.tem-tsp.eu URI = https:// | ||
| - | ...done | ||
| - | Creating cookie encryption key files... | ||
| - | ...done | ||
| - | Rebuilding / | ||
| - | ...done | ||
| - | |||
| - | BUILD SUCCESSFUL | ||
| </ | </ | ||
| Line 284: | Line 245: | ||
| < | < | ||
| - | [root@idp3 shibboleth-identity-provider-3.2.1]# ls -l / | + | [root@idp34 shibboleth-identity-provider-3.4.2]# ls -l / |
| total 32 | total 32 | ||
| - | -rw-r--r-- 1 root root 1168 23 mai 22:14 idp-backchannel.crt | + | -rw-r--r-- 1 root root 1517 2 janv. 14:23 idp-backchannel.crt |
| - | -rw-r--r-- 1 root root 2554 23 mai 22:14 idp-backchannel.p12 | + | -rw-r--r-- 1 root root 3399 2 janv. 14:23 idp-backchannel.p12 |
| - | -rw-r--r-- 1 root root 1164 23 mai 22:14 idp-encryption.crt | + | -rw-r--r-- 1 root root 1517 2 janv. 14:23 idp-encryption.crt |
| - | -rw------- 1 root root 1675 23 mai 22:14 idp-encryption.key | + | -rw------- 1 root root 2455 2 janv. 14:23 idp-encryption.key |
| - | -rw-r--r-- 1 root root 1164 23 mai 22:14 idp-signing.crt | + | -rw-r--r-- 1 root root 1517 2 janv. 14:23 idp-signing.crt |
| - | -rw------- 1 root root 1675 23 mai 22:14 idp-signing.key | + | -rw------- 1 root root 2459 2 janv. 14:23 idp-signing.key |
| - | -rw-r--r-- 1 root root | + | -rw-r--r-- 1 root root |
| - | -rw-r--r-- 1 root root 48 23 mai 22:14 sealer.kver | + | -rw-r--r-- 1 root root 47 2 janv. 14:23 sealer.kver |
| </ | </ | ||
| Line 299: | Line 260: | ||
| < | < | ||
| - | [root@idp3 shibboleth-identity-provider-3.2.1]# chown -R tomcat / | + | [root@idp34 shibboleth-identity-provider-3.4.2]# chown -R tomcat / |
| </ | </ | ||
| Line 315: | Line 276: | ||
| </ | </ | ||
| - | quelques secondes apres | + | quelques secondes apres grace a l' |
| < | < | ||
| - | root@idp3 localhost]# ls -l / | + | [root@idp34 shibboleth-identity-provider-3.4.2]# ls -l / |
| total 32 | total 32 | ||
| - | drwxr-xr-x 2 tomcat tomcat 4096 25 mai 20:38 css | + | drwxr-xr-x 2 tomcat tomcat 4096 2 janv. 14:28 css |
| - | drwxr-xr-x 2 tomcat tomcat 4096 25 mai 20:38 images | + | drwxr-xr-x 2 tomcat tomcat 4096 2 janv. 14:28 images |
| - | -rw-r--r-- 1 tomcat tomcat 1008 23 mai 22:14 index.jsp | + | -rw-r--r-- 1 tomcat tomcat 1008 2 janv. 14:23 index.jsp |
| - | drwxr-xr-x 2 tomcat tomcat 4096 25 mai 20:38 js | + | drwxr-xr-x 2 tomcat tomcat 4096 2 janv. 14:28 js |
| - | drwxr-xr-x 2 tomcat tomcat 4096 25 mai 20:38 META-INF | + | drwxr-xr-x 2 tomcat tomcat 4096 2 janv. 14:28 META-INF |
| - | drwxr-xr-x 5 tomcat tomcat 4096 25 mai 20:38 WEB-INF | + | drwxr-xr-x 5 tomcat tomcat 4096 2 janv. 14:28 WEB-INF |
| - | -rw-r--r-- 1 tomcat tomcat | + | -rw-r--r-- 1 tomcat tomcat |
| </ | </ | ||
| Line 342: | Line 304: | ||
| en effet il faut ajouter la librairie jstl (cf http:// | en effet il faut ajouter la librairie jstl (cf http:// | ||
| - | cf aussi https:// | + | cf aussi https:// |
| < | < | ||
| - | [root@idp3 ~]# cd / | + | [root@idp34 shibboleth-identity-provider-3.4.2]# cd / |
| - | [root@idp3 lib]# wget http:// | + | [root@idp34 lib]# wget http:// |
| - | [root@idp3 lib]# systemctl restart tomcat | + | 2019-01-02 14:34:08 (9,27 MB/s) - «jstl-1.2.jar» sauvegardé [414240/ |
| + | [root@idp34 lib]# systemctl restart tomcat | ||
| </ | </ | ||
| + | Pour l' | ||
| + | |||
| + | < | ||
| + | # vim / | ||
| + | < | ||
| + | ... | ||
| + | < | ||
| + | |||
| + | <entry key=" | ||
| + | <bean id=" | ||
| + | p: | ||
| + | </ | ||
| + | ... | ||
| + | </ | ||
| + | |||
| + | |||
| + | maintenant accessible en https:// | ||
| acces status possible en shell également | acces status possible en shell également | ||
| < | < | ||
| - | [root@idp3 ~]# / | + | [root@idp34 bin]# / |
| ### Operating Environment Information | ### Operating Environment Information | ||
| operating_system: | operating_system: | ||
| - | operating_system_version: | + | operating_system_version: |
| operating_system_architecture: | operating_system_architecture: | ||
| - | jdk_version: | + | jdk_version: |
| - | available_cores: | + | available_cores: |
| - | used_memory: | + | used_memory: |
| maximum_memory: | maximum_memory: | ||
| ### Identity Provider Information | ### Identity Provider Information | ||
| - | idp_version: | + | idp_version: |
| - | start_time: | + | start_time: |
| - | current_time: | + | current_time: |
| - | uptime: | + | uptime: |
| - | service: shibboleth.LoggingService | ||
| - | last successful reload attempt: 2016-06-21T08: | ||
| - | last reload attempt: 2016-06-21T08: | ||
| - | .... | ||
| </ | </ | ||
| - | Pour l' | ||
| - | < | ||
| - | CT-a84f4e90 shibboleth-identity-provider-3.3.0# | ||
| - | < | ||
| - | ... | ||
| - | < | ||
| - | |||
| - | <entry key=" | ||
| - | <bean id=" | ||
| - | p: | ||
| - | </ | ||
| - | ... | ||
| - | </ | ||
| Line 424: | Line 387: | ||
| < | < | ||
| - | [root@idp3 shibboleth-idp]# wget -O / | + | [root@idp34]# cd / |
| + | [root@idp34 credentials]# | ||
| </ | </ | ||
| Line 431: | Line 396: | ||
| < | < | ||
| [root@idp3 conf]# tail -18 metadata-providers.xml | [root@idp3 conf]# tail -18 metadata-providers.xml | ||
| + | |||
| + | < | ||
| + | < | ||
| + | xsi: | ||
| + | backingFile=" | ||
| + | metadataURL=" | ||
| + | |||
| + | < | ||
| + | requireSignedRoot=" | ||
| + | certificateFile=" | ||
| + | </ | ||
| + | </ | ||
| + | |||
| | | ||
| - | <!-- Federation de test renater --> | + | |
| - | < | + | |
| - | xsi: | + | |
| - | backingFile=" | + | |
| - | metadataURL=" | + | |
| - | + | ||
| - | < | + | |
| - | requireSignedRoot=" | + | |
| - | certificateFile=" | + | |
| - | </ | + | |
| - | < | + | |
| - | < | + | |
| - | </ | + | |
| </ | </ | ||
| Line 454: | Line 420: | ||
| < | < | ||
| - | [root@idp3 conf]# systemctl restart tomcat.service | + | [root@idp34 conf]# systemctl restart tomcat.service |
| - | [root@idp3 conf]# ls -l ../ | + | |
| - | total 6480 | + | [root@idp34 conf]# |
| - | -rw-r--r-- | + | total 31308 |
| - | -rw-r--r-- | + | -rw-r--r-- 1 tomcat root |
| + | -rw-r--r-- 1 tomcat tomcat | ||
| </ | </ | ||
| Line 468: | Line 436: | ||
| idp-process.log : | idp-process.log : | ||
| - | 2016-06-21 18:55:56,043 - INFO [org.opensaml.saml.metadata.resolver.impl.AbstractReloadingMetadataResolver: | + | |
| - | 2016-06-21 18:55:56,062 - INFO [Shibboleth-Audit.Reload: | + | 2019-01-02 14:48:18,248 - 127.0.0.1 - INFO [org.opensaml.saml.metadata.resolver.impl.AbstractReloadingMetadataResolver:574] - Metadata Resolver FileBackedHTTPMetadataResolver RenaterTestMetadata: New metadata successfully loaded for ' |
| + | 2019-01-02 14:48:18,250 - 127.0.0.1 | ||
| + | 2019-01-02 14:48:18,268 - 127.0.0.1 | ||
| + | |||
| </ | </ | ||
| Line 680: | Line 652: | ||
| https:// | https:// | ||
| - | < | ||
| - | [root@idp3]# | ||
| - | [root@idp3 src]# git clone https:// | + | < |
| - | Cloning into 'shib-cas-authn3-git-master' | + | [root@idp34 src]# wget https:// |
| - | remote: Counting objects: 1172, done. | + | [root@idp34 src]# tar xvf shib-cas-authn3-3.2.3.tar |
| - | remote: Total 1172 (delta 0), reused 0 (delta 0), pack-reused 1172 | + | ... |
| - | Receiving objects: 100% (1172/1172), 991.61 KiB | 884.00 KiB/s, done. | + | shib-cas-authn3-3.2.3/edit-webapp/ |
| - | Resolving deltas: 100% (427/427), done. | + | shib-cas-authn3-3.2.3/edit-webapp/ |
| + | shib-cas-authn3-3.2.3/edit-webapp/ | ||
| + | .. | ||
| - | [root@idp3 src]# cp -R /opt/src/shib-cas-authn3-git-master/IDP_HOME/ | + | [root@idp34 src]# cp shib-cas-authn3-3.2.3/edit-webapp/WEB-INF/lib/ |
| - | [root@idp3 src]# wget https:// | + | |
| - | [root@idp3 src]# mv shib-cas-authenticator-3.0.0.jar / | + | |
| - | [root@idp3 src]# wget http:// | + | |
| - | [root@idp3 src]# mv cas-client-core-3.3.3.jar / | + | [root@idp34 src]# cp -R shib-cas-authn3-3.2.3/ |
| + | [root@idp34 src]# ls -ltr /opt/ | ||
| + | total 8 | ||
| + | -rw-r--r-- 1 root root 2290 2 janv. 21:23 shibcas-authn-flow.xml | ||
| + | -rw-r--r-- 1 root root 3241 2 janv. 21:23 shibcas-authn-beans.xml | ||
| + | [root@idp34 src]# wget http:// | ||
| + | [root@idp34 src]# cp cas-client-core-3.5.1.jar / | ||
| </ | </ | ||
| Line 726: | Line 701: | ||
| < | < | ||
| + | |||
| + | [root@idp34 conf]# cd / | ||
| + | [root@idp34 authn]# cp general-authn.xml general-authn.xml.dist | ||
| + | |||
| [root@idp3 authn]# diff general-authn.xml general-authn.xml.dist | [root@idp3 authn]# diff general-authn.xml general-authn.xml.dist | ||
| 93,98d92 | 93,98d92 | ||