shibboleth-dev - EPPN via AA echo context?
Subject: Shibboleth Developers
List archive
- From: "RL 'Bob' Morgan" <>
- To: Shib Design Team <>
- Subject: EPPN via AA echo context?
- Date: Thu, 26 Dec 2002 16:16:55 -0800 (PST)
The origin deploy doc says that the AA Echo context will supply both
ePAffil of member and EPPN, but EPPN isn't working for my UWash origin.
I fiddled with the ARP settings in the AA, that is, in the file
/usr/local/tomcat/webapps/shibboleth/WEB-INF/conf/arps/admin, so it now
says:
% ArpUtil list admin
ARP: admin(admin)
SHAR: no.other.match(default)
URL: * [*]
eduPersonAffiliation
eduPersonPrincipalName
which I think says to release EPPN.
Tomcat is getting the REMOTE_USER env var (confirmed via snoop.jsp).
But my test app only ever gets:
HTTP_SHIB_EP_AFFILIATION ==
""
Now it is a (mis-)feature of my local signon system that REMOTE_USER is
expressed as an unscoped userid, ie "rlmorgan" rather than
""
(or actually
""
which
is the official Kerb principal). It isn't clear to me whether the origin
code is expecting REMOTE_USER to be unscoped or not.
When I test using the Example U origin I also only get member@, but I
assume that's the way that origin is set.
So, any enlightenment here? Are others successfully releasing EPPN?
Twould be nice to demo some apps that need userid.
Thanks,
- RL "Bob"
------------------------------------------------------mace-shib-design-+
For list utilities, archives, subscribe, unsubscribe, etc. please visit the
ListProc web interface at
http://archives.internet2.edu/
------------------------------------------------------mace-shib-design--
- EPPN via AA echo context?, RL 'Bob' Morgan, 12/26/2002
- RE: EPPN via AA echo context?, Scott Cantor, 12/26/2002
- RE: EPPN via AA echo context?, RL 'Bob' Morgan, 12/26/2002
- RE: EPPN via AA echo context?, Scott Cantor, 12/27/2002
- RE: EPPN via AA echo context?, RL 'Bob' Morgan, 12/26/2002
- Re: EPPN via AA echo context?, RL 'Bob' Morgan, 12/26/2002
- RE: EPPN via AA echo context?, Scott Cantor, 12/26/2002
Archive powered by MHonArc 2.6.16.