This shows you the differences between two versions of the page.
Both sides previous revision Previous revision Next revision | Previous revision | ||
docpublic:systemes:shibboleth:spv2c7 [2015/06/04 20:39] procacci@tem-tsp.eu [native.log] |
docpublic:systemes:shibboleth:spv2c7 [2017/02/21 09:42] (current) procacci@tem-tsp.eu [Réference] |
||
---|---|---|---|
Line 5: | Line 5: | ||
* https:// | * https:// | ||
* https:// | * https:// | ||
- | * https://federation.renater.fr/ | + | * https://services.renater.fr/federation/ |
* https:// | * https:// | ||
* https:// | * https:// | ||
Line 24: | Line 24: | ||
< | < | ||
# yum install shibboleth | # yum install shibboleth | ||
+ | |||
Dependencies Resolved | Dependencies Resolved | ||
- | ================================================================================================= | + | ============================================================================================================================================ |
- | | + | |
- | ================================================================================================= | + | ============================================================================================================================================ |
Installing: | Installing: | ||
- | | + | |
Installing for dependencies: | Installing for dependencies: | ||
- | | + | |
- | | + | |
- | | + | |
- | | + | |
- | | + | |
- | | + | |
- | | + | |
- | | + | |
- | | + | |
- | | + | |
- | | + | |
- | | + | |
Transaction Summary | Transaction Summary | ||
- | ============================================================= | + | ====================================================================================================================================== |
Install | Install | ||
Total download size: 5.1 M | Total download size: 5.1 M | ||
Installed size: 28 M | Installed size: 28 M | ||
- | Is this ok [y/d/N]: y | ||
Line 58: | Line 58: | ||
< | < | ||
- | Installed: | + | Installed: |
- | shibboleth.x86_64 0:2.5.4-3.2 | + | shibboleth.x86_64 0:2.5.5-3.1 |
</ | </ | ||
Line 65: | Line 65: | ||
==== demarrage automatique ==== | ==== demarrage automatique ==== | ||
+ | |||
+ | je conseil d' | ||
< | < | ||
- | [root@wood yum.repos.d]# | ||
- | shibd.service | ||
- | [root@wood yum.repos.d]# | + | [root@wikis yum.repos.d]# |
- | shibd.service | + | ln -s '/ |
- | Executing | + | |
- | The unit files have no [Install] section. They are not meant to be enabled | + | |
- | using systemctl. | + | |
- | Possible reasons for having this kind of units are: | + | |
- | 1) A unit may be statically enabled by being symlinked from another unit' | + | |
- | .wants/ | + | |
- | 2) A unit's purpose may be to act as a helper for some other unit which has | + | |
- | a requirement dependency on it. | + | |
- | 3) A unit may be started when needed via activation (socket, path, timer, | + | |
- | | + | |
- | [root@wood yum.repos.d]# | + | |
- | Note: This output shows SysV services only and does not include native | + | [root@wikis shibboleth]# |
- | | + | [root@wikis shibboleth]# |
- | systemd | + | shibd.service - Shibboleth Service Provider Daemon |
+ | | ||
+ | | ||
+ | Main PID: 668 (shibd) | ||
+ | | ||
+ | `-668 / | ||
- | If you want to list systemd | + | Aug 07 17:31:14 wikis systemd[1]: Started Shibboleth Service Provider Daemon. |
- | To see services enabled on particular target use | + | |
- | ' | + | |
- | + | ||
- | shibd 0: | + | |
</ | </ | ||
- | et manuel la premiere fois: | ||
- | |||
- | < | ||
- | # / | ||
- | </ | ||
Ainsi que httpd restart / reload pour charger le mod_shib contenu dans / | Ainsi que httpd restart / reload pour charger le mod_shib contenu dans / | ||
Line 146: | Line 131: | ||
Acces: | Acces: | ||
- | * http://www-pub.it-sudparis.eu/ | + | * http://wood.tem-tsp.eu/ |
les metadata directement: | les metadata directement: | ||
- | * http://www-pub.it-sudparis.eu/ | + | * http://wood.tem-tsp.eu/ |
+ | ==== test config ==== | ||
+ | attention à la libCurl et openssl : | ||
+ | |||
+ | from https:// | ||
+ | |||
+ | < | ||
+ | even if the message is marked as critical, those errors can be ignored. On many RedHat/ | ||
+ | |||
+ | LD_LIBRARY_PATH=/ | ||
+ | </ | ||
===== Parametrage shibboleth2.xml ===== | ===== Parametrage shibboleth2.xml ===== | ||
Line 164: | Line 159: | ||
< | < | ||
- | < | + | < |
| | ||
- | ... | + | |
+ | .. | ||
< | < | ||
<SSO | <SSO | ||
Line 194: | Line 190: | ||
<!-- Chains together all your metadata sources. --> | <!-- Chains together all your metadata sources. --> | ||
< | < | ||
- | |||
- | |||
< | < | ||
Federation IT /> | Federation IT /> | ||
--> | --> | ||
- | |||
< | < | ||
backingFilePath="/ | backingFilePath="/ | ||
Line 220: | Line 213: | ||
[root@wood shibboleth]# | [root@wood shibboleth]# | ||
[root@wood shibboleth]# | [root@wood shibboleth]# | ||
+ | </ | ||
+ | |||
+ | |||
+ | ==== Certificats de signature des metadata ==== | ||
+ | |||
+ | cf https:// | ||
+ | |||
+ | certificat Renater | ||
+ | |||
+ | < | ||
+ | [root@wood shibboleth]# | ||
+ | |||
</ | </ | ||
Line 230: | Line 235: | ||
* https:// | * https:// | ||
+ | |||
+ | avant de generer une nouvelle paire de clée, il est preferable de sauvegarder la paire initiale (car le -f / force les ecrasera ) | ||
+ | |||
+ | < | ||
+ | [root@wood shibboleth]# | ||
+ | [root@wood shibboleth]# | ||
+ | </ | ||
générer la paire de clé pour l' | générer la paire de clé pour l' | ||
< | < | ||
- | [root@colmut | + | [root@wood shibboleth]# |
Generating a 2048 bit RSA private key | Generating a 2048 bit RSA private key | ||
- | ......+++ | + | ............................................................................................+++ |
- | .....................................................................................+++ | + | ....................+++ |
writing new private key to ' | writing new private key to ' | ||
----- | ----- | ||
- | [root@colmut shibboleth]# | ||
- | [root@colmut shibboleth]# | ||
- | [root@colmut | + | [root@wood shibboleth]# |
+ | [root@wood shibboleth]# | ||
+ | |||
+ | [root@wood shibboleth]# | ||
</ | </ | ||
Line 251: | Line 265: | ||
< | < | ||
... | ... | ||
- | < | + | < |
REMOTE_USER=" | REMOTE_USER=" | ||
- | < | + | < |
</ | </ | ||
- | |||
</ | </ | ||
</ | </ |