Re: Shibboleth authentication for Roundup

"John P. Rouillard" <[email protected]>
Newsgroups gmane.comp.bug-tracking.roundup.user
Message-ID <[email protected]>
Hi Tonu:

In message
<[email protected].
com>,

Tonu Mikk writes:
[Georg wrote:] 
>You could rather do something like:
>
>   AliasMatch  ^/(?!Shibboleth.sso)(.*)
>/swadm/roundup/trackers/wcag/html/dummy.py/$1
>
>This did the trick and Shibboleth login began to work.  Thank you
>Georg for thinking about this and providing an answer!
>
>In case this is of interest... by default Shibboleth returns the
>Remote-User attribute in the form of an email.  In order to make
>Shibboleth work with Roundup, I needed to change the username
>into an email address to match the Remote_User value.

Would you be willing to write up the key parts of your apache config
and roundup config and post it on the wiki for people looking for it
in the future?

If so let me know and I'll send you the info you need to create an
account. If you want to write it I can add it to the wiki and credit
you.

I was also going to mention that there should be a way by creating a
new login action to do a lookup by email address and map that to a
user. However REMOTE_USER bypasses that mechanism.

I think using the the web server to authenticate against Kerberos or
AD will return domain\user as the REMOTE_USER. Being able to change
that value would be useful.

Does anybody think we need to open a ticket to add the ability to
map/process the REMOTE_USER variable?

Have a great day and congrats Tonu on getting the login working.

--
				-- rouilj
John Rouillard
===========================================================================
My employers don't acknowledge my existence much less my opinions.

------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.