Installing SP2.x under Linux: Difference between revisions

From RavenWiki
Jump to navigationJump to search
(Note that Internet" aparently now support some SuSE distrbutions)
(Updated for new revsions (and source) of binary RPMs)
Line 1: Line 1:
Currently these instructions apply specifically to installs on SLES 10 using UCS-supplied RPMs (which support i386 and x86_64 architectures). See [https://spaces.internet2.edu/display/SHIB2/NativeSPLinuxInstall NativeSPLinuxInstall] in the Internet2 Wiki for instructions on installing in other versions of Linux, and then adapt these instructions accordingly. Note that Internet2 distribute [https://spaces.internet2.edu/display/SHIB2/NativeSPLinuxRPMInstall binary RPMs for CentOS versions 4 and 5 on i386 and x86_64 architectures] and that source RPMs corresponding to the UCS distribution [http://www.internet2.edu/ are also available]. [Note that  (as of October 2009) the situation appears to have changed and Internet2 now apparently distribute binary RPMs for at least some SuSE products].
These instructions apply specifically to installs on SLES 10 using Internet2-supplied RPMs, which currently (March 2010) support CentOS 5, RHEL 4 and 5, SUSE Linux Enterprise Server 9, 10, 11, and OpenSUSE Linux 11.0 and 11.1), all in i386 and x86_64 versions. See [https://spaces.internet2.edu/display/SHIB2/NativeSPLinuxInstall NativeSPLinuxInstall] in the Internet2 Wiki for instructions on installing in other versions of Linux, and then adapt these instructions accordingly.


Currently these instructions also assumes you are using the ''prefork'' version Apache - this may or may not all work with ''worker''. We also assume that your web server serves a single site - [[Virtual hosting issues with Shibboleth | virtual hosting issues]] are addressed later.
Currently these instructions also assumes you are using the ''prefork'' version Apache - this may or may not all work with ''worker''. We also assume that your web server serves a single site - [[Virtual hosting issues with Shibboleth | virtual hosting issues]] are addressed later.


Download and install SLES 10 RPMs from [http://raven.cam.ac.uk/project/shibboleth/files/RPMS/SLES10/ the Raven project site]. Download and install the latest RPM for each of the following (you can ignore devel, debuginfo, or docs packages):  
Download and install the apropriate RPMs from OpenSUSE project's Build Service at http://download.opensuse.org/repositories/security://shibboleth/]. Download and install the latest RPM for each of the following (you can ignore devel, debuginfo, or docs packages):  


  log4shib  
  log4shib  
Line 12: Line 12:
  shibboleth  
  shibboleth  


and any of their dependencies.
and any of their dependencies. The Build Service will act as a Yum repository, allowing various package managers to interact with it directly. Details vary between distributions and package managers, but for SLES10 and <tt>zypper</tt> the apropriate repository can be added with


In /etc/shibboleth:
zypper sa http://download.opensuse.org/repositories/security:/shibboleth/SLE_10/
* replace the supplied shibboleth2.xml and attribute-map.xml with [[Shibboleth2.xml - internal use skeleton]] and [[Attribute-map.xml - internal use skeleton]] respectively (copies also installed by the RPMs in files with names ending UCAMSKEL)
 
after which the Shibboleth software can be installed with
zypper in shibboleth
 
After installing the software, in /etc/shibboleth:
* replace the supplied shibboleth2.xml and attribute-map.xml with [[Shibboleth2.xml - internal use skeleton]] and [[Attribute-map.xml - internal use skeleton]] respectively.
* find all occurrences of 'FIX-ME' in the new shibboleth2.xml and replace them as directed in the adjacent comments (see [[Editing XML]] and [[EntityIDs]] for useful background).
* find all occurrences of 'FIX-ME' in the new shibboleth2.xml and replace them as directed in the adjacent comments (see [[Editing XML]] and [[EntityIDs]] for useful background).



Revision as of 15:33, 4 March 2010

These instructions apply specifically to installs on SLES 10 using Internet2-supplied RPMs, which currently (March 2010) support CentOS 5, RHEL 4 and 5, SUSE Linux Enterprise Server 9, 10, 11, and OpenSUSE Linux 11.0 and 11.1), all in i386 and x86_64 versions. See NativeSPLinuxInstall in the Internet2 Wiki for instructions on installing in other versions of Linux, and then adapt these instructions accordingly.

Currently these instructions also assumes you are using the prefork version Apache - this may or may not all work with worker. We also assume that your web server serves a single site - virtual hosting issues are addressed later.

Download and install the apropriate RPMs from OpenSUSE project's Build Service at http://download.opensuse.org/repositories/security://shibboleth/]. Download and install the latest RPM for each of the following (you can ignore devel, debuginfo, or docs packages):

log4shib 
xerces-c 
xml-security-c
xmltooling
opensaml 
shibboleth 

and any of their dependencies. The Build Service will act as a Yum repository, allowing various package managers to interact with it directly. Details vary between distributions and package managers, but for SLES10 and zypper the apropriate repository can be added with

zypper sa http://download.opensuse.org/repositories/security:/shibboleth/SLE_10/

after which the Shibboleth software can be installed with

zypper in shibboleth

After installing the software, in /etc/shibboleth:

Run (as root)

 /usr/sbin/shibd -t

and expect to see "overall configuration is loadable, check console for non-fatal problems". Fix any reported mistakes.

Start shibd (as root) with

 /etc/init.d/shibd start

[Note: "Starting shibd listener failed to enter listen loop" means that you were not root]. See /var/log/shibboleth/shibd.log for startup messages. The Shibboleth RPM will have already set shibd to restart on boot.

(Re-)start Apache. In case of failure see /var/log/apache2/error_log

Access http://<hostname>/secure/. You should be redirected to Raven to authenticate, be asked to accept release of your information, and then see a 404 error page from your server (because you have no content in the requested location). See /var/log/apache2/error_log, /var/log/shibboleth/shibd.log and /var/log/shibboleth/transaction.log for clues if something goes wrong. Feel free to create some content in /srv/www/htdocs/secure/ for a better demonstration.

Assuming this works, visit http://<hostname>/Shibboleth.sso/Session to check that attribute information is being released to your SP. You should see a page containing something like:

 Attributes
 ----------
 affiliation: member@cam.ac.uk;member@eresources.lib.cam.ac.uk
 entitlement: urn:mace:dir:entitlement:common-lib-terms
 eppn: fjc55@cam.ac.uk

You now have a web server running the Shibboleth SP software and protecting the content of http://<hostname>/secure/ by requiring an authenticated Raven login (by anyone). Where you go from here depends on what you want to do. Topics to consider include: