This shows you the differences between two versions of the page.
| Both sides previous revision Previous revision Next revision | Previous revision | ||
|
docpublic:systemes:shibboleth:spv2c7 [2015/06/04 20:37] procacci@tem-tsp.eu [Metadata] |
docpublic:systemes:shibboleth:spv2c7 [2017/02/21 09:42] (current) procacci@tem-tsp.eu [Réference] |
||
|---|---|---|---|
| Line 5: | Line 5: | ||
| * https:// | * https:// | ||
| * https:// | * https:// | ||
| - | * https://federation.renater.fr/ | + | * https://services.renater.fr/federation/ |
| * https:// | * https:// | ||
| * https:// | * https:// | ||
| Line 24: | Line 24: | ||
| < | < | ||
| # yum install shibboleth | # yum install shibboleth | ||
| + | |||
| Dependencies Resolved | Dependencies Resolved | ||
| - | ================================================================================================= | + | ============================================================================================================================================ |
| - | | + | |
| - | ================================================================================================= | + | ============================================================================================================================================ |
| Installing: | Installing: | ||
| - | | + | |
| Installing for dependencies: | Installing for dependencies: | ||
| - | | + | |
| - | | + | |
| - | | + | |
| - | | + | |
| - | | + | |
| - | | + | |
| - | | + | |
| - | | + | |
| - | | + | |
| - | | + | |
| - | | + | |
| - | | + | |
| Transaction Summary | Transaction Summary | ||
| - | ============================================================= | + | ====================================================================================================================================== |
| Install | Install | ||
| Total download size: 5.1 M | Total download size: 5.1 M | ||
| Installed size: 28 M | Installed size: 28 M | ||
| - | Is this ok [y/d/N]: y | ||
| Line 58: | Line 58: | ||
| < | < | ||
| - | Installed: | + | Installed: |
| - | shibboleth.x86_64 0:2.5.4-3.2 | + | shibboleth.x86_64 0:2.5.5-3.1 |
| </ | </ | ||
| Line 65: | Line 65: | ||
| ==== demarrage automatique ==== | ==== demarrage automatique ==== | ||
| + | |||
| + | je conseil d' | ||
| < | < | ||
| - | [root@wood yum.repos.d]# | ||
| - | shibd.service | ||
| - | [root@wood yum.repos.d]# | + | [root@wikis yum.repos.d]# |
| - | shibd.service | + | ln -s '/ |
| - | Executing | + | |
| - | The unit files have no [Install] section. They are not meant to be enabled | + | |
| - | using systemctl. | + | |
| - | Possible reasons for having this kind of units are: | + | |
| - | 1) A unit may be statically enabled by being symlinked from another unit' | + | |
| - | .wants/ | + | |
| - | 2) A unit's purpose may be to act as a helper for some other unit which has | + | |
| - | a requirement dependency on it. | + | |
| - | 3) A unit may be started when needed via activation (socket, path, timer, | + | |
| - | | + | |
| - | [root@wood yum.repos.d]# | + | |
| - | Note: This output shows SysV services only and does not include native | + | [root@wikis shibboleth]# |
| - | | + | [root@wikis shibboleth]# |
| - | systemd | + | shibd.service - Shibboleth Service Provider Daemon |
| + | | ||
| + | | ||
| + | Main PID: 668 (shibd) | ||
| + | | ||
| + | `-668 / | ||
| - | If you want to list systemd | + | Aug 07 17:31:14 wikis systemd[1]: Started Shibboleth Service Provider Daemon. |
| - | To see services enabled on particular target use | + | |
| - | ' | + | |
| - | + | ||
| - | shibd 0: | + | |
| </ | </ | ||
| - | et manuel la premiere fois: | ||
| - | |||
| - | < | ||
| - | # / | ||
| - | </ | ||
| Ainsi que httpd restart / reload pour charger le mod_shib contenu dans / | Ainsi que httpd restart / reload pour charger le mod_shib contenu dans / | ||
| Line 109: | Line 94: | ||
| - | ==== native.log ==== | + | ==== emplacement des fichiers de log ==== |
| + | |||
| + | definis dans les fichier .logger : | ||
| < | < | ||
| - | [root@blog3 /var/log/httpd] | + | [root@wood shibboleth]# |
| - | $ touch native.log | + | native.logger: |
| - | [root@blog3 | + | native.logger: |
| - | $ chown apache native.log | + | shibd.logger: |
| + | shibd.logger: | ||
| + | shibd.logger: | ||
| + | shibd.logger: | ||
| </ | </ | ||
| Line 139: | Line 131: | ||
| Acces: | Acces: | ||
| - | * http://www-pub.it-sudparis.eu/ | + | * http://wood.tem-tsp.eu/ |
| les metadata directement: | les metadata directement: | ||
| - | * http://www-pub.it-sudparis.eu/ | + | * http://wood.tem-tsp.eu/ |
| + | ==== test config ==== | ||
| + | attention à la libCurl et openssl : | ||
| + | |||
| + | from https:// | ||
| + | |||
| + | < | ||
| + | even if the message is marked as critical, those errors can be ignored. On many RedHat/ | ||
| + | |||
| + | LD_LIBRARY_PATH=/ | ||
| + | </ | ||
| ===== Parametrage shibboleth2.xml ===== | ===== Parametrage shibboleth2.xml ===== | ||
| Line 157: | Line 159: | ||
| < | < | ||
| - | < | + | < |
| | | ||
| - | ... | + | |
| + | .. | ||
| < | < | ||
| <SSO | <SSO | ||
| Line 187: | Line 190: | ||
| <!-- Chains together all your metadata sources. --> | <!-- Chains together all your metadata sources. --> | ||
| < | < | ||
| - | |||
| - | |||
| < | < | ||
| Federation IT /> | Federation IT /> | ||
| --> | --> | ||
| - | |||
| < | < | ||
| backingFilePath="/ | backingFilePath="/ | ||
| Line 213: | Line 213: | ||
| [root@wood shibboleth]# | [root@wood shibboleth]# | ||
| [root@wood shibboleth]# | [root@wood shibboleth]# | ||
| + | </ | ||
| + | |||
| + | |||
| + | ==== Certificats de signature des metadata ==== | ||
| + | |||
| + | cf https:// | ||
| + | |||
| + | certificat Renater | ||
| + | |||
| + | < | ||
| + | [root@wood shibboleth]# | ||
| + | |||
| </ | </ | ||
| Line 223: | Line 235: | ||
| * https:// | * https:// | ||
| + | |||
| + | avant de generer une nouvelle paire de clée, il est preferable de sauvegarder la paire initiale (car le -f / force les ecrasera ) | ||
| + | |||
| + | < | ||
| + | [root@wood shibboleth]# | ||
| + | [root@wood shibboleth]# | ||
| + | </ | ||
| générer la paire de clé pour l' | générer la paire de clé pour l' | ||
| < | < | ||
| - | [root@colmut | + | [root@wood shibboleth]# |
| Generating a 2048 bit RSA private key | Generating a 2048 bit RSA private key | ||
| - | ......+++ | + | ............................................................................................+++ |
| - | .....................................................................................+++ | + | ....................+++ |
| writing new private key to ' | writing new private key to ' | ||
| ----- | ----- | ||
| - | [root@colmut shibboleth]# | ||
| - | [root@colmut shibboleth]# | ||
| - | [root@colmut | + | [root@wood shibboleth]# |
| + | [root@wood shibboleth]# | ||
| + | |||
| + | [root@wood shibboleth]# | ||
| </ | </ | ||
| Line 244: | Line 265: | ||
| < | < | ||
| ... | ... | ||
| - | < | + | < |
| REMOTE_USER=" | REMOTE_USER=" | ||
| - | < | + | < |
| </ | </ | ||
| - | |||
| </ | </ | ||
| </ | </ | ||