Dear indico administrators,
We are trying to setup SSO to work with “mellon” . We are able to access our SSO login page but after entering the login information it just spins and it seems that indico does not recognize the information.
The following is the indico.conf setup:
# SSO
AUTH_PROVIDERS = {
'shib-sso': {
'type': 'shibboleth',
'title': 'Fermilab SSO',
'attrs_prefix': 'SSO_',
'callback_uri': '/login/shib-sso/shibboleth'
#, 'logout_uri': 'https://indicodev.fnal.gov/mellon/logout'
}
}
IDENTITY_PROVIDERS = {
'shib-sso': {
'type': 'shibboleth',
'title': 'Fermilab SSO',
'identifier_field': 'SSO_USERID',
'mapping': {
'email': 'SSO_EMAIL',
'login': 'SSO_USERID',
'personId': 'SSO_USERID',
'last_name': 'SSO_NAME_LAST',
'first_name': 'SSO_NAME_FIRST'
},
'trusted_email': True
}
}
The apache access.log has the following entries:
131.225.80.21 - - [01/May/2018:09:30:49 -0500] "GET /login/ HTTP/1.1" 200 15765 "https://indicodev.fnal.gov/" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029 .110 Safari/537.36"
131.225.80.21 - - [01/May/2018:09:30:49 -0500] "GET /images/logo_indico.png HTTP/1.1" 200 12586 "https://indicodev.fnal.gov/login/" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36"
131.225.80.21 - - [01/May/2018:09:30:52 -0500] "GET /login/shib-sso/ HTTP/1.1" 302 259 "https://indicodev.fnal.gov/login/" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36"
131.225.80.21 - - [01/May/2018:09:30:52 -0500] "GET /login/shib-sso/shibboleth HTTP/1.1" 303 376 "https://indicodev.fnal.gov/login/" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36"
131.225.80.21 - - [01/May/2018:09:30:52 -0500] "GET /mellon/login?ReturnTo=https%3A%2F%2Findicodev.fnal.gov%2Flogin%2Fshib%2Dsso%2Fshibboleth&IdP=https%3A%2F%2Fidp.fnal.gov%2Fidp%2Fshibboleth HTTP/1 .1" 303 1285 "https://indicodev.fnal.gov/login/" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36"
131.225.80.21 - - [01/May/2018:09:30:52 -0500] "GET /login/shib-sso/shibboleth HTTP/1.1" 303 376 "https://pingprod.fnal.gov:9031/" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36"
131.225.80.21 - - [01/May/2018:09:30:52 -0500] "GET /mellon/login?ReturnTo=https%3A%2F%2Findicodev.fnal.gov%2Flogin%2Fshib%2Dsso%2Fshibboleth&IdP=https%3A%2F%2Fidp.fnal.gov%2Fidp%2Fshibboleth HTTP/1 .1" 303 1315 "https://pingprod.fnal.gov:9031/" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36"
131.225.80.21 - - [01/May/2018:09:30:53 -0500] "GET /login/shib-sso/shibboleth HTTP/1.1" 303 376 "https://pingprod.fnal.gov:9031/" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36"
131.225.80.21 - - [01/May/2018:09:30:53 -0500] "GET /mellon/login?ReturnTo=https%3A%2F%2Findicodev.fnal.gov%2Flogin%2Fshib%2Dsso%2Fshibboleth&IdP=https%3A%2F%2Fidp.fnal.gov%2Fidp%2Fshibboleth HTTP/1 .1" 303 1293 "https://pingprod.fnal.gov:9031/" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36"
131.225.80.21 - - [01/May/2018:09:30:53 -0500] "GET /login/shib-sso/shibboleth HTTP/1.1" 303 376 "https://pingprod.fnal.gov:9031/" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36"
131.225.80.21 - - [01/May/2018:09:30:53 -0500] "GET /mellon/login?ReturnTo=https%3A%2F%2Findicodev.fnal.gov%2Flogin%2Fshib%2Dsso%2Fshibboleth&IdP=https%3A%2F%2Fidp.fnal.gov%2Fidp%2Fshibboleth HTTP/1 .1" 303 1275 "https://pingprod.fnal.gov:9031/" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36"
131.225.80.21 - - [01/May/2018:09:30:53 -0500] "GET /login/shib-sso/shibboleth HTTP/1.1" 303 376 "https://pingprod.fnal.gov:9031/" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36"
131.225.80.21 - - [01/May/2018:09:30:53 -0500] "GET /mellon/login?ReturnTo=https%3A%2F%2Findicodev.fnal.gov%2Flogin%2Fshib%2Dsso%2Fshibboleth&IdP=https%3A%2F%2Fidp.fnal.gov%2Fidp%2Fshibboleth HTTP/1 .1" 303 1297 "https://pingprod.fnal.gov:9031/" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36"
131.225.80.21 - - [01/May/2018:09:30:54 -0500] "GET /login/shib-sso/shibboleth HTTP/1.1" 303 376 "https://pingprod.fnal.gov:9031/" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36"
131.225.80.21 - - [01/May/2018:09:30:54 -0500] "GET /mellon/login?ReturnTo=https%3A%2F%2Findicodev.fnal.gov%2Flogin%2Fshib%2Dsso%2Fshibboleth&IdP=https%3A%2F%2Fidp.fnal.gov%2Fidp%2Fshibboleth HTTP/1 .1" 303 1295 "https://pingprod.fnal.gov:9031/" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36"
.....
.....
We would appreciate your help on how to setup mellon.
Best regards
Penelope