|Status:||Closed||Start date:||Nov 17, 2015|
|Priority:||Low||Due date:||Nov 27, 2015|
|Assignee:||Massimiliano Assante||% Done:|
|Sprint:||Federated Login on D4Science Gateways|
The federated login should be enabled on services and iMarine Gateways, in particular the INFN of Catania should be added as Federated authority
#2 Updated by Massimiliano Assante over 3 years ago
- Estimated time set to 16.00
- Status changed from New to In Progress
- Due date changed from Nov 20, 2015 to Nov 27, 2015
We have a solution (in place and working) for SAML2.0 / Shibboleth implementation into the gCube portal implemented by ENG in iMarine.
We use it for https://social.isti.cnr.it and we federated our institute (ISTI) identity provider to the D4Science Service provider running on https://sp.d4science.org/casshib/shib/app2/login (2-3 years ago)
We never enabled it for the other D4Science gateways because until now we never had another request by any other institute. However since the INFN of Catania requested SAML it should be enabled.
#3 Updated by Massimiliano Assante over 3 years ago
I was able, by following the wiki guide made by @email@example.com for iMarine in WP5 to install the shibboleth-ds rpm (iMarine Custom Discovery Service) on the D4Science service provider VM (sp.d4science.org)
I also configured Liferay (of dev.d4science.org) to use CASShib. Now, in the case of unique Idp I am able to login (with the ISTI dip), when I switch to multi iDP instead it get redirected to the iMarine Custom Discovery Service (https://sp.d4science.org/shibboleth-ds/index.html) but I get a blank page and no error in the tomcat logs.
I looked at the WIKI here: https://wiki.gcube-system.org/gcube/Shibboleth_and_gCube#Discovery_Service and I saw that I miss the configurations needed for loading the trusted IdPs ('/casshib/shib/app2/Shibboleth.sso/DiscoFeed')
Can anybody help with this? @firstname.lastname@example.org ? Perhaps I'm getting a blank page because I miss the DiscoFeed file?
#8 Updated by Massimiliano Assante over 3 years ago
- % Done changed from 0 to 50
The problem with the Discovery Service not being displayed was solved by @email@example.com , now we need to fill it with the federated institutes.
Also, the main page of the Discovery service (D4Science) has been themed for the D4Science Infrastructure (https://sp.d4science.org/shibboleth-ds/index.html)
#9 Updated by Massimiliano Assante over 3 years ago
- % Done changed from 50 to 70
- Assignee changed from Ciro Formisano to Massimiliano Assante
Discovery Service is ready, it can be accessed from http://dev.d4science.org and clicking on SAML Federation, we need to contact INFN Catania for creating the trust between our Service Provider and their Identity Provider. The Trusting of IDP Isti is already set and works.