Repository navigation
Does mellon protect multiple URL with single metadata file of IdP #49
Description
Activity
- changed the title
[-]Does mellon protect multiple URL with single metadata file of IDP[/-][+]Does mellon protect multiple URL with single metadata file of IdP[/+]on Feb 17, 2021 Maybe you can describe what exact config you tried and what is logged when you get the Bad Request response.
I'm using Apache with Mellon module as a reverse proxy (SP) in front of a web app. Actually we are planning to protect 100+ URLs.
For test cases:--
We created metadata file and certificate for https://app1-pp.mydomain.com from SP and shared it with IdP(ForgeRock).
IdP created and configured metadata file and shared it with me. Then, I did configuration at apache level and app1 URL is working fine. -
So we had plan to add app2 URL in SAML SSO authentication using previous same entityID and same IdP metadata. I had asked to IdP to add 2nd URL in same previous configuration. Then, I did configuration at apache level. After this is done we're getting "Bad Request" Error..
While "Bad Request" error did not get any logs at apache.
Question:- Can we configure and protect multiple URLs with single entityID and IdP metadata ?
URLs:-
https://app1-pp.mydomain.com
https://app2.pp.s3-in.mydomain.comApache Veriosn:- Apache 2.4
Idp:- ForgeRockMellon Configuration
<location /> MellonSPPrivateKeyFile /etc/httpd/mellon/app1.key MellonSPCertFile /etc/httpd/mellon/app1.cert MellonSPMetadataFile /etc/httpd/mellon/app1.xml MellonIdPMetadataFile /etc/httpd/mellon/CGDevsamltestpp1vstd.xml MellonEndpointPath /mellon MellonEnable "info" MellonVariable "cookie" #MellonSecureCookie On MellonCookiePath / MellonUser "NAME_ID" MellonSessionDump Off MellonSamlResponseDump Off MellonEndpointPath "/mellon" MellonDefaultLoginPath "/" MellonSessionLength 43200 </Location>Get Request XML
<samlp:AuthnRequest xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol" xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" ID="_72551C09B0AFEA1378FFC214694D2A0F" Version="2.0" IssueInstant="2021-02-17T11:28:10Z" Destination="https://sso.Mydomain.com:443/opensso/SSORedirect/metaAlias/Mydomain/IDPsamltestpp" Consent="urn:oasis:names:tc:SAML:2.0:consent:current-implicit" ForceAuthn="false" IsPassive="false" AssertionConsumerServiceURL="https://app1-pp.mydomain.com/mellon/postResponse" > <saml:Issuer>https://app1-pp.mydomain.com/</saml:Issuer> <samlp:NameIDPolicy Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient" AllowCreate="true" /> </samlp:AuthnRequest>Response Request XML
<samlp:Response xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol" Destination="https://app1-pp.mydomain.com/mellon/postResponse" ID="s2c242212e02cf6423ca6ee4edcb0d2db460347926" InResponseTo="_72551C09B0AFEA1378FFC214694D2A0F" IssueInstant="2021-02-17T11:28:17Z" Version="2.0" > <saml:Issuer xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion">CGDevsamltestpp</saml:Issuer> <ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> <ds:SignedInfo> <ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#" /> <ds:SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256" /> <ds:Reference URI="#s2c242212e02cf6423ca6ee4edcb0d2db460347926"> <ds:Transforms> <ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature" /> <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#" /> </ds:Transforms> <ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256" /> <ds:DigestValue>9QCFx9F0W5XOYj1tMpR4lMljYK6dwjFjsA7Kmzsnik4=</ds:DigestValue> </ds:Reference>-
Hello Kinkhorst,
Can you help me if you have any idea about my requirement ?
- locked and limited conversation to collaborators
on Feb 19, 2021
Hello,
I have hosted multiple URLs on apache server and help of mellon protect all URLs but earlier I have tested with single URL and working fine.
But 2nd scenarios is that I need to protect all URLs with single metadata file of IdP and getting error such as "Bad Request" for new add URL.
Does mellon module support for multiple URL to protect with single metadata file of IdP ?