<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Shibboleth configuration in Nuxeo Forum</title>
    <link>https://connect.hyland.com/t5/nuxeo-forum/shibboleth-configuration/m-p/314450#M1451</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I'm trying to use Shibboleth but have some issues.
My configuration :&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Apache 2.2 with mod_proxy. A virtual host and inside the virtual host a location /nuxeo protected by shibboleth (i.e AuthType shibboleth). Inside this virtual host a ProxyPass directive to the tomcat nuxeo using ajp.&lt;/LI&gt;
&lt;LI&gt;A SP installed on the same machine&lt;/LI&gt;
&lt;LI&gt;and finally on the same machine, my nuxeo 5.5 with a template embedding the 2 shibboleth plugins (login and group)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The flow when I'm accessing the https://&lt;SERVERNAME&gt;/nuxeo/ is :
1- Apache check Shibboleth access : A) first time no access so I'm being redirected to the DiscoveryService then to the B) Login page. C) After log in the browser is redirected to the Discovery Service. If I inspect the /Shibboleth.sso/Session on my SP I saw an active session...
It's like Apache is OK with the authentification, pass the request to Nuxeo which doesn't find the shibboleth session and ask me to login. (using the loginURL provided in the &lt;EXTENSION target="org.nuxeo.ecm.platform.shibboleth.service.ShibbolethAuthenticationService"&gt;).&lt;/EXTENSION&gt;&lt;/SERVERNAME&gt;&lt;/P&gt;
&lt;P&gt;What do I put in the loginURL tag ?&lt;/P&gt;
&lt;P&gt;I don't really understand why ?
If someone can explain the cause and the solution,
thanks in advance.&lt;/P&gt;</description>
    <pubDate>Wed, 31 Oct 2012 22:43:16 GMT</pubDate>
    <dc:creator>Kahlua_</dc:creator>
    <dc:date>2012-10-31T22:43:16Z</dc:date>
    <item>
      <title>Shibboleth configuration</title>
      <link>https://connect.hyland.com/t5/nuxeo-forum/shibboleth-configuration/m-p/314450#M1451</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I'm trying to use Shibboleth but have some issues.
My configuration :&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Apache 2.2 with mod_proxy. A virtual host and inside the virtual host a location /nuxeo protected by shibboleth (i.e AuthType shibboleth). Inside this virtual host a ProxyPass directive to the tomcat nuxeo using ajp.&lt;/LI&gt;
&lt;LI&gt;A SP installed on the same machine&lt;/LI&gt;
&lt;LI&gt;and finally on the same machine, my nuxeo 5.5 with a template embedding the 2 shibboleth plugins (login and group)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The flow when I'm accessing the https://&lt;SERVERNAME&gt;/nuxeo/ is :
1- Apache check Shibboleth access : A) first time no access so I'm being redirected to the DiscoveryService then to the B) Login page. C) After log in the browser is redirected to the Discovery Service. If I inspect the /Shibboleth.sso/Session on my SP I saw an active session...
It's like Apache is OK with the authentification, pass the request to Nuxeo which doesn't find the shibboleth session and ask me to login. (using the loginURL provided in the &lt;EXTENSION target="org.nuxeo.ecm.platform.shibboleth.service.ShibbolethAuthenticationService"&gt;).&lt;/EXTENSION&gt;&lt;/SERVERNAME&gt;&lt;/P&gt;
&lt;P&gt;What do I put in the loginURL tag ?&lt;/P&gt;
&lt;P&gt;I don't really understand why ?
If someone can explain the cause and the solution,
thanks in advance.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2012 22:43:16 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/nuxeo-forum/shibboleth-configuration/m-p/314450#M1451</guid>
      <dc:creator>Kahlua_</dc:creator>
      <dc:date>2012-10-31T22:43:16Z</dc:date>
    </item>
  </channel>
</rss>

