Installing SP2.x under OSX

From RavenWiki
Revision as of 08:19, 9 July 2012 by jwrn3 (talk | contribs)
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to navigationJump to search

Installing/Configuring Shibboleth for OS Server 10.6.8

Legacy info here: Installing SP2.x under MacOS

Install MacPorts & Shibboleth

Method 1

Download and install OS X Developer Tools from (you may need to create an account first)

Download Mac Ports from and install the .pkg

Open Terminal and type:

sudo port selfupdate

sudo port install shibboleth

The installation of Shibboleth and supporting software will take some time.

Method 2

Install the package from This software is built for 32/64 bit intel and should work on 10.5 and later.

Once installed you need to create the OpenSSL certificates:

sudo /opt/local/etc/shibboleth/

Enable SSL

Using Server Admin select Web | Sites pane, choose the website and enable SSL from the security tab

Configure Apache

Add the following to the /etc/apache2/httpd.conf file:

Include /opt/local/etc/shibboleth/apache22.config

If you are not using apache v2.2 then edit the above line appropriately according to the contents of the /opt/local/etc/shibboleth/ directory.

Ensure that the ServerName directive is set correctly and UseCanonicalName is set to On in /etc/apache2/httpd.conf

Configure Shibboleth

$ cd /opt/local/etc/shibboleth/

$ sudo curl -o shibboleth2.xml

$ sudo curl -o attribute-map.xml

Edit the config files and look for the FIX-ME flags highlighting required edits to the files. See for more info.

Once configured check the syntax with:

$ /opt/local/sbin/shibd -t

A correctly configured install will return 'overall configuration is loadable, check console for non-fatal problems'. If not, check syntax and try again.

Starting the service

Set shib to load at startup:

$ sudo launchctl load -w /opt/local/etc/LaunchDaemons/org.macports.shibd/org.macports.shibd.plist

Start Apache:

$ sudo serveradmin start web

Before you can proceed any further you will need to register you SP, at least with Raven. See SP registration for details

Test your page by going to

Reloading the service

Any changes to the shib config require shibd and apache to be reloaded:

sudo launchctl unload -w /opt/local/etc/LaunchDaemons/org.macports.shibd/org.macports.shibd.plist

sudo launchctl load -w /opt/local/etc/LaunchDaemons/org.macports.shibd/org.macports.shibd.plist

sudo apachectl restart

You may care to script this to save your sanity when making lots of changes/testing..


Check the following locations for logging info:






More information

Most of this document was cribbed together from the following sources: