Skip to Content.
Sympa Menu

shibboleth-dev - Re: [Shib-Dev] Debugging shibboleth-idp-ext-delegation [SOLVED]

Subject: Shibboleth Developers

List archive

Re: [Shib-Dev] Debugging shibboleth-idp-ext-delegation [SOLVED]


Chronological Thread 
  • From: Halm Reusser <>
  • To:
  • Subject: Re: [Shib-Dev] Debugging shibboleth-idp-ext-delegation [SOLVED]
  • Date: Fri, 23 Jul 2010 09:49:38 +0200

Hi Brent,

Brent Putman wrote:

Ok, it's definitely not running the security policy, at least, there's no
log output for the delegation-specific rules for client cert auth and assertion token validation. So it's almost certainly the case that the relying-party.xml config is incorrect in some way [...]

You got it. I've verified the relying-party.xml again and indeed in the
following ProfileConfiguration was missing in the DefaultRelyingParty:

<ProfileConfiguration xsi:type="samldel:LibertyIDWSFSSOSProfile"
allowTokenDelegation="false"
signAssertions="always"
encryptNameIds="never"
securityPolicyRef="shibboleth.ext.delegation.LibertySSOSPolicy"/>

Thanks for the hints, have a nice weekend.

-Halm



Archive powered by MHonArc 2.6.16.

Top of Page