Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

There are five configuration files

FilenameLocation on SP
Comments
Notes
idp-metadata.xml

/etc/shibboleth/idp-metadata.xml

A copy of your site's IdP metadata
sp-metadata.xml

/var/www/html/sp-metadata.xml 

– if your Apache sets DocumentRoot to /var/www 

(

To be shared dynamically with your site's Shibboleth IdP.

Or omit from the SP, and instead email it to IdP admins

)To be shared with your site's Shibboleth IdP

attribute-map.xml /etc/shibboleth/attribute-map.xml Specifies the user-information that your IdP sends to Sp upon login
sp.conf/etc/httpd/conf.d/sp.conf

Tells Apache to require Shibboleth login for Shrine Urls (/shrine-api/*) .

Tomcat should open port 8080 only to localhost, and should reside on the same host as your SP

shibboleth2.xml/etc/shibboleth/shibboleth2.xmlSpecifies miscellaneous aspects of your SP

Each of these files needs to adjusted to the particulars of your site, your requirements. 

You can search for the marker: 'ADJUST_FOR_YOUR_SITE' in those files for indications of what / where you need to edit.


...

More-Detailed Discussion of Shibboleth Considerations

...