【问题标题】:Environment variables from Shibboleth not being passed when using ProxyPass使用 ProxyPass 时未传递来自 Shibboleth 的环境变量
【发布时间】:2016-10-09 04:40:50
【问题描述】:

我正在使用带有 Apache (w/ mod_proxy) 的 Shibboleth,并且我注意到诸如 REMOTE_USER 之类的环境变量并没有完全进入我的应用程序。

我有一个看起来像这样的虚拟主机:

<VirtualHost *:443>
  ServerName example.com

  <Location /Shibboleth.sso>
    ProxyPass !
  </Location>

  ProxyPass / http://127.0.0.1:9292/
  ProxyPassReverse / http://127.0.0.1:9292/

  ...
</VirtualHost>

请求被代理传递给运行带有 Puma 网络服务器的 Ruby on Rails 应用程序,但是当我检查 request.ENV 时,我看不到我的 shibboleth 属性。有没有人有这样的经历?

【问题讨论】:

  • 您是否指定要使用 AuthType shibboleth?如果您认为虚拟主机是正确的,请验证您是否设置了要从 IdP 提取 saml 消息的属性(在您的 sp 中,默认情况下请参见 attribute-map.xml)
  • ..... 然后设置 REMOTE_USER 您可以设置这些属性的优先级列表,请参阅此处的示例wiki.shibboleth.net/confluence/display/SHIB2/…

标签: apache mod-proxy vhosts shibboleth


【解决方案1】:

在您的 Apache 配置中设置 ShibUseHeaders: AuthType shibboleth ShibRequireSession 开启 ShibUseHeaders 开启 需要有效用户

那么你应该将属性设置为“HTTP_VARNAME”并在 request.ENV 之外使用它们

【讨论】:

    猜你喜欢
    • 1970-01-01
    • 1970-01-01
    • 2019-12-08
    • 1970-01-01
    • 2018-09-18
    • 1970-01-01
    • 1970-01-01
    • 2018-12-02
    • 1970-01-01
    相关资源
    最近更新 更多