Opensso FAQWord文件下载.docx

上传人:b****1 文档编号:433778 上传时间:2023-04-28 格式:DOCX 页数:19 大小:22.92KB
下载 相关 举报
Opensso FAQWord文件下载.docx_第1页
第1页 / 共19页
Opensso FAQWord文件下载.docx_第2页
第2页 / 共19页
Opensso FAQWord文件下载.docx_第3页
第3页 / 共19页
Opensso FAQWord文件下载.docx_第4页
第4页 / 共19页
Opensso FAQWord文件下载.docx_第5页
第5页 / 共19页
Opensso FAQWord文件下载.docx_第6页
第6页 / 共19页
Opensso FAQWord文件下载.docx_第7页
第7页 / 共19页
Opensso FAQWord文件下载.docx_第8页
第8页 / 共19页
Opensso FAQWord文件下载.docx_第9页
第9页 / 共19页
Opensso FAQWord文件下载.docx_第10页
第10页 / 共19页
Opensso FAQWord文件下载.docx_第11页
第11页 / 共19页
Opensso FAQWord文件下载.docx_第12页
第12页 / 共19页
Opensso FAQWord文件下载.docx_第13页
第13页 / 共19页
Opensso FAQWord文件下载.docx_第14页
第14页 / 共19页
Opensso FAQWord文件下载.docx_第15页
第15页 / 共19页
Opensso FAQWord文件下载.docx_第16页
第16页 / 共19页
Opensso FAQWord文件下载.docx_第17页
第17页 / 共19页
Opensso FAQWord文件下载.docx_第18页
第18页 / 共19页
Opensso FAQWord文件下载.docx_第19页
第19页 / 共19页
亲,该文档总共19页,全部预览完了,如果喜欢就下载吧!
下载资源
资源描述

Opensso FAQWord文件下载.docx

《Opensso FAQWord文件下载.docx》由会员分享,可在线阅读,更多相关《Opensso FAQWord文件下载.docx(19页珍藏版)》请在冰点文库上搜索。

Opensso FAQWord文件下载.docx

false"

WantAssertionsSigned="

protocolSupportEnumeration="

protocol"

SingleLogoutServiceBinding="

bindings:

HTTP-Redirect"

Location="

https:

//localhost:

8080/openfm-samples-ip/IDPSloRedirect/metaAlias/ip_meta_alias"

/>

NameIDFormat>

1.1:

nameid-format:

emailAddress<

/NameIDFormat>

AssertionConsumerServiceisDefault="

true"

index="

0"

Binding="

HTTP-POST"

3000/account/complete"

/>

/SPSSODescriptor>

/EntityDescriptor>

AndthenintheAuthrequestmyNameIDpolicyissomethinglike(inRuby):

"

samlp:

NameIDPolicy"

+

xmlns:

samlp=\"

protocol\"

Format=\"

emailAddress\"

SPNameQualifier=\"

"

+@sp_name_qualifier+"

\"

AllowCreate=\"

true\"

\n"

/samlp:

NameIDPolicy>

ButIgeta500errorwithopenssologgingthistothedebug/Federationlog:

libSAML2:

11/12/200810:

50:

13:

779AMCST:

Thread[httpSSLWorkerThread-8080-0,10,Grizzly]

ERROR:

IDPSSOFederate.doSSOFederate:

Unabletodossoorfederation.

mon.SAML2Exception:

UnabletogenerateNameIDvalue.

atcom.sun.identity.saml2.plugins.DefaultIDPAccountMapper.getNameID(DefaultIDPAccountMapper.java:

143)

atcom.sun.identity.saml2.profile.IDPSSOUtil.getSubject(IDPSSOUtil.java:

1378)

atcom.sun.identity.saml2.profile.IDPSSOUtil.getAssertion(IDPSSOUtil.java:

794)

atcom.sun.identity.saml2.profile.IDPSSOUtil.getResponse(IDPSSOUtil.java:

651)

atcom.sun.identity.saml2.profile.IDPSSOUtil.sendResponseToACS(IDPSSOUtil.java:

342)

atcom.sun.identity.saml2.profile.IDPSSOFederate.doSSOFederate(IDPSSOFederate.java:

569)

InOpenSSOIseethattheIDP(IclickontheFederationtabandclickonthehostedIDPentity)IseetheNameIDformatof

emailAddress}}isincludedandaNameIDvaluemapentryof{{urn:

emailAddress=mailalongwithsomeothers.

HowIcangetOpenSSOtoreturnthe"

mail"

asthe"

emailAdress"

?

Resolution

TheexceptionmeansthatIDPisunabletofinduser'

s'

mail'

attributefromdatastore.

Makesurethatyouareloggedinastheuserwithanemailaddress.

ossoScribes:

BacktoTop

Browserthrows500errorduringSSO

WhiletheuserisperformingSSO,thebrowsershowshttp500errorwith"

InvalidConfiguration"

.

AnerrormessagesimilartotheexamplebelowiswrittentotheamSAML.errorlog:

ThetargetsiteismissingfromtheURL

∙CheckconfigurationfileandmakesureSAMLintersitetransferurlcanpickupthe"

TARGET"

site.

∙Onthebrowser,theintersitetransferurlshouldlooklike:

http:

//hostname:

port/amserver/SAMLAwareServlet?

TARGET=http(s):

//....&

SAMLArt=

....

ThiserrornormaloccursduetothevalueoftheTARGETparameterisemptyorTARGETparameterismissingfromtheaboveurl.Sincetheparameterintheurlquerystringiscasesensitive,iftheusertype

target=..."

insteadof"

TARGET=..."

theywouldgetthiserroraswell.

ThereisnotrustedsitespecifiedintheSAMLservicemanagement"

Anerrormessagesimilartotheexamplebelowiswrittentothebrowseronly.ThereisnotrustedsitespecifiedintheSAMLservicemanagement.

∙LogintoSunJavaSystemIdentityServer2004Q2console.Theurlshouldlookslike:

http(s):

port/amconsole

∙Clickon"

ServiceConfiguration"

tab

∙Ontheleftsideoftheframe,select"

SAML"

as"

ServiceName"

∙Ontherightsideoftheframe,find"

TrustedPartnerSites"

addoneormultipleentries.

BacktoTop

destIDisnotintheTrustedPartnerSites"

AnerrormessagesimilartotheexamplebelowiswrittentotheamSAMLdebug:

IntersiteTransfer:

FailedtocreateAssertionArtifact(s).

AssertionManager.createAssertionArtifact(String,String):

destIDnotinpartnerlist.

∙Verifythatthedestinationpageidisintheconfiguration.

oIfitisnot,re-enterconfigurationdataandverifythatthereisaDestUrlnamed<

destination_page_id>

oOtherwise,verifythatthehostnameofthisbankingagentisintheconfiguration.

∙Inashell,type`hostname`withoutthesinglequotes.

∙WiththeControlCenter,verifythatthishostnameislistedasanAppHost

∙LogintotheOpenSSOconsole.MakesurethisdestIDison"

SAMLExceptionwhenexecutinggetAssertionsmethod

TheusertriestogetasetofAssertionsbycallingAssertionManagerClientclass'

smethodpublic{{SetgetAssertions(SSOTokentoken)

throwsSAMLException}}

andgetsSAMLException:

NoprivilegetoperformthetaskThisAPIisnormallyusedonclient/agent/sdksite.

AssertionManager.getAssertions(SSOToken):

SSOTokendoesn'

thavetheprivilege

Checkiftheuser'

sroleistopleveladminrole.Ifnot,theuserneedstoupgradeitsroletothetopleveladminroleinordertousethismethod.

SAMLExceptionwhenexecutinggetAssertionArtifactsmethod

TheusertriestogetasetofAssertionArtifactsbycallingAssertionManagerClientclass'

smethodpublic{{SetgetAssertionArtifacts(SSOTokentoken)

andgets{{SAMLException:

Noprivilegetoperformthetask.}}ThisAPIisnormallyusedonclient/agent/sdksite.

SAMLExceptionwhenexecutinggetAssertionByArtifactmethod

TheusertriestogetAssertionwiththeinputAssertionArtifactbycallingSAMLClientclass'

smethodpublicstaticAssertiongetAssertionByArtifact(Stringartifact)

andget{{SAMLException:

FailedincreatingSOAPURLEndpoint}}

AnerrormessagesimilartotheexamplebelowiswrittentotheamSAMLdebug

SAMLClient:

artifactQueryHandler:

createSOAPReceiverURLError!

Resoultion

WiththeOpenSSOconsole,makesurethatthereis"

SOAPUrl"

attributedefinedinacertainentryon"

list.

WhiletheuserisperformingSSO,thebrowsershowshttp500error.

AuthTypeandtheprotocol(basedonSOAPUrl)donotmatch

WiththeOpenSSOconsole,makesurethatattribute"

AuthType"

matchestheprotocolof"

soapurl"

attributedefinedin"

List.

AuthTypecouldbeSSL,SSLWITHBASICAUTH,NOAUTH,BASICAUTH.If"

isonhttps,wemustspecifyAuthType=SSLorSSLWITHBASICAUTH.

SAMLClient:

artifactQueryHandler

com.sun.xml.messaging.saaj.SOAPExceptionImpl:

java.security.PrivilegedActionException:

Messagesendfailed

atcom.sun.xml.messaging.saaj.client.p2p.HttpSOAPConnection.call(HttpSOAPConnection.java:

...)

OntheOpenSSOconsole,makesurethatthe"

entryiscorrect.

ThereisnoreplyfromSAMLSOAPReceiver

Theusershouldcheckwhether"

isanactiveone.

Couldn'

tverifytheResponse.

ThisproblemnormallyrelatestothemisconfigurationofsamlkeystoreinAMConfig.propertiesfile.

First,theusershouldlookintoamSAMLdebugtofindoutwhythesignatureofsamlresponsecannotbevalidated.

Second,theusershouldrecheckthefollowingentriesinOpenSSO.com.sun.identity.saml.xmlsig.keystore=/opt/SUNWam/sun-1-sign.jks

com.sun.identity.saml.xmlsig.storepass=/opt/SUNWam/.storepass

com.sun.identity.saml.xmlsig.keypass=/opt/SUNWam/.keypass

com.sun.identity.saml.xmlsig.certalias=testcert

Third,theuserneedtomakesurethedirectorywhichleadstothekeystore,storepass,keypassfilesindeedexistandarecorrect.Atlast,theusershouldusethecommand:

keytool-list-aliastestcert-keystore/opt/SUNWam/sun-1-sign.jks

tolistwhetherthesigningcertindeedisinthekeystore.

BuildingofassertionfailswithSAMLVersionMismatchException

Theuser'

sapplicationcallsSAMLsdk,specificallyAssertionconstructortobuildanAssertion.ItcouldfailwithSAML

展开阅读全文
相关资源
猜你喜欢
相关搜索

当前位置:首页 > 党团工作 > 其它

copyright@ 2008-2023 冰点文库 网站版权所有

经营许可证编号:鄂ICP备19020893号-2