Re: SAML problems when updating to 6.6.2

"Robert T. Wilson" <[email protected]>
Newsgroups gmane.education.ezproxy
Message-ID <[email protected]>
Hi Kasper,

I’ve just updated on our test instance, and it has broken our Azure SSO setup. I’ll experiment with settings info you provided from documentation, and let you know if I make any progress.

Thanks for heads up!

Robert

Robert Wilson
Systems Librarian, Assistant Professor
James E Walker Library
Middle Tennessee State University

From: EZproxy List <[email protected]> on behalf of Kasper Løvschall <[email protected]>
Date: Friday, September 27, 2019 at 7:13 AM
To: "[email protected]" <[email protected]>
Subject: [EZPROXY-L] SAML problems when updating to 6.6.2

Dear all,

Today I updated two installations from EZproxy version 6.5.1 to 6.6.2 and immediately our SAML login (ADFS) stopped working with a: SAML Response is not signed; signature is required.

When I downgraded back to version 6.5.1 everything started working again. Something changed in the SAML part of EZproxy.

And, so it did according to the release notes:
Configuration option to change default from encryption of attributes to no encryption
Some SAML services do not accepted encrypted attributes. To allow EZproxy to interact with more local SAML services, we have expanded the ShibollethMetadata configuration options.
The ShibbolethMetadata config.txt now has three new options when processing a Response document from an IdP:

  *   SignResponse=[true|false] determines whether or not the Response document must be signed.  The default value is true consistent with past EZproxy requirements.
  *   SignAssertion=[true|false] determines whether or not the Assertion within the Response must be signed.  The default value is false consistent with past EZproxy requirements, but see upgrade warning below.
  *   EncryptAssertion=[true|false] determine whether or not the Assertion within the Response document must be encrypted.  The default is true consistent with past EZproxy requirements.
To maximize security, we recommend leaving the default settings in effect, but these values are now configurable to meet the unique site needs.
But as I read this I would expect that: as long as I haven’t made any changes things are working as they did in previous versions? And I don’t see the mentioned upgrade warning anywhere in here<https://help.oclc.org/Library_Management/EZproxy/EZproxy_release_notes_and_known_issues/2019_release_notes/050EZproxy_v6_6_2_release_notes> (unless it is the: leave things as default if possible). Any one experiencing SAML issues with the latest version?

Thanks,
Kasper Løvschall




[au_en]

Kasper Løvschall
Chief Consultant  | The University Library

Phone: (+45) 99 40 73 03  |  Mobile: (+45) 28 95 91 29  |  Email: [email protected]<mailto:[email protected]>  |  Web: https://www.en.aub.aau.dk
Aalborg University Library  |  Langagervej 2  |  9220 Aalborg Ø  |  Denmark


________________________________

To unsubscribe from the EZPROXY-L list, click the following link:
http://listserv.oclclists.org/scripts/wa.exe?SUBED1=EZPROXY-L&A=1

********************************************************************
If you wish to stop receiving messages from EZPROXY-L or otherwise amend your preferences,
you can do so <a href="https://www.oclc.org/forms/internet-subscription.en.html">here</a>.
Or email [email protected] including the relevant text below in the body of the email:
• To unsubscribe: "unsubscribe EZPROXY-L"
• To receive EZPROXY-L in digest form: "set EZPROXY-L digest"
• To set your options to no mail: "set EZPROXY-L nomail"
• To receive these messages in the future "set EZPROXY-L mail"
To contact the list owners directly please send your message to [email protected].
If you unsubscribe from EZPROXY-L, you will no longer be able to participate in any of its features, including the public forum.
To unsubscribe from all OCLC marketing email communications
(including all OCLC listervs, OCLC Connect emails, OCLC event notifications, product/service/cooperative updates and newsletters),
please email us at [email protected].
image001.png (image/png, 5 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.