<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>John McLear &#187; testing</title>
	<atom:link href="http://mclear.co.uk/category/testing/feed/" rel="self" type="application/rss+xml" />
	<link>http://mclear.co.uk</link>
	<description>My mission: To encourage effective use of ICT in Schools. My main focus is on ages 3-11.</description>
	<lastBuildDate>Sat, 04 Feb 2012 14:22:04 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://primaryblogger.co.uk/?v=3.3.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Testing Shibboleth SP 2 on CentOS to the ukfederation w/ Godaddy certs</title>
		<link>http://mclear.co.uk/2009/10/27/testing-shibboleth-sp-2-on-centos-to-the-ukfederation-w-godaddy-certs/</link>
		<comments>http://mclear.co.uk/2009/10/27/testing-shibboleth-sp-2-on-centos-to-the-ukfederation-w-godaddy-certs/#comments</comments>
		<pubDate>Tue, 27 Oct 2009 15:39:00 +0000</pubDate>
		<dc:creator>Admin Admin</dc:creator>
				<category><![CDATA[janet]]></category>
		<category><![CDATA[shibboleth]]></category>
		<category><![CDATA[testing]]></category>

		<guid isPermaLink="false">http://mclear.primaryblogger.co.uk/2009/10/27/testing-shibboleth-sp-2-on-centos-to-the-ukfederation-w-godaddy-certs/</guid>
		<description><![CDATA[Part 4. Testing (2 hours) Shibboleth can be started using /sbin/service shibd start Another option is to use: service shibd restart If the above doesn&#8217;t work try /usr/sbin/shibd -f If you are going to use different commands to start shibd ensure that multiple copies are not running by doing ps aux &#124; grep shibd If [...]]]></description>
			<content:encoded><![CDATA[<div><strong>Part 4. Testing (2 hours)</strong></div>
<div><strong><br />
</strong></div>
<div>Shibboleth can be started using <strong>/sbin/service shibd start</strong></div>
<div>Another option is to use: <strong>service shibd restart</strong></div>
<div>If the above doesn&#8217;t work try <strong>/usr/sbin/shibd -f</strong></div>
<div><strong><br />
</strong></div>
<div>If you are going to use different commands to start shibd ensure that multiple copies are not running by doing <strong>ps aux | grep shibd</strong></div>
<div><strong><br />
</strong></div>
<div>If you see shibd -f &amp; /usr/sbin/shibd&#8230;..  then you need to kill them and start one.  I recommend using <strong>service shibd start.</strong></div>
<div><strong><br />
</strong></div>
<div>Log files will be in:<strong> /var/log/shibboleth/</strong></div>
<div><strong><br />
</strong></div>
<div>Check the shibd.log file for errors using this command: <strong>cat /var/log/shibboleth/shibd.log | grep ERROR</strong></div>
<div>Your resource URL is <strong>https://shib.yourdomain.com/secure </strong></div>
<div>Try browse to it.</div>
<div>If you get nothing then Apache hasn&#8217;t started properly, check the apache logs.</div>
<div>You should get something that starts with the shibboleth logo OR a WAYF login screen.</div>
<div>If you get the WAYF screen the things are going great, if you get the Shibboleth error message then we need to make some more configuration changes.  See your logs and continue reading.</div>
<div>
<div>If you get &#8220;Cannot connect to shibd process, a site adminstrator should be notified.&#8221;</div>
<div>then your SELINUX restrictions have kicked in.  Check by doing</div>
<div><strong>cat /var/log/audit/audit.log | grep shib</strong></div>
<div><strong><br />
</strong></div>
<div>More info on SELinux can be found here or by using the <strong>sestatus </strong>command:</div>
<div><strong><span style="font-weight: normal"><br />
</span></strong></div>
<div>
<div>A good output should look like this:</div>
<blockquote>
<div>SELinux status:                 enabled</div>
<div>SELinuxfs mount:                /selinux</div>
<div>Current mode:                   permissive</div>
<div>Mode from config file:          enforcing</div>
<div>Policy version:                 21</div>
<div>Policy from config file:        targeted</div>
</blockquote>
<p>The fix for the SELinux problem is documented on Page 1 however I recommend being a bit more brutal if your environment is hyper fussy about security.</p>
</div>
<div>Once you have a working setup you can browse to <strong>http://shib.yourdomain.com/Shibboleth.sso/Metadata</strong> to get your automatically generated Metadata and proceed with the UK Federation registration process.</div>
<div>When you speak to the UK Federation to approve your registration you will be asked to run this command from /etc/shibboleth</div>
<div><strong>openssl x509 -sha1 -in sp.crt -noout -fingerprint</strong></div>
<div><strong><br />
</strong></div>
<div>You will be asked to provide them with the fingerprint so keep a record of this.</div>
<div>
<div></div>
<div style="text-align: right">Griffin goes &#8220;meow&#8221;.</div>
</div>
</div>


<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center shr-bookmarks-bg-caring">
<ul class="socials">
		<li class="shr-comfeed">
			<a href="http://mclear.co.uk/2009/10/27/testing-shibboleth-sp-2-on-centos-to-the-ukfederation-w-godaddy-certs/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-delicious">
			<a href="http://www.shareaholic.com/api/share/?title=Testing+Shibboleth+SP+2+on+CentOS+to+the+ukfederation+w%2F+Godaddy+certs&amp;link=http://mclear.co.uk/2009/10/27/testing-shibboleth-sp-2-on-centos-to-the-ukfederation-w-godaddy-certs/&amp;notes=Part%204.%20Testing%20%282%20hours%29%0D%0A%0D%0A%0D%0AShibboleth%20can%20be%20started%20using%20%2Fsbin%2Fservice%20shibd%20start%0D%0AAnother%20option%20is%20to%20use%3A%20service%20shibd%20restart%0D%0AIf%20the%20above%20doesn%27t%20work%20try%20%2Fusr%2Fsbin%2Fshibd%20-f%0D%0A%0D%0A%0D%0AIf%20you%20are%20going%20to%20use%20different%20commands%20to%20start%20shibd%20ensure%20that%20multiple%20copies%20are%20not%20running%20by%20do&amp;short_link=&amp;shortener=none&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=2&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-digg">
			<a href="http://www.shareaholic.com/api/share/?title=Testing+Shibboleth+SP+2+on+CentOS+to+the+ukfederation+w%2F+Godaddy+certs&amp;link=http://mclear.co.uk/2009/10/27/testing-shibboleth-sp-2-on-centos-to-the-ukfederation-w-godaddy-certs/&amp;notes=Part%204.%20Testing%20%282%20hours%29%0D%0A%0D%0A%0D%0AShibboleth%20can%20be%20started%20using%20%2Fsbin%2Fservice%20shibd%20start%0D%0AAnother%20option%20is%20to%20use%3A%20service%20shibd%20restart%0D%0AIf%20the%20above%20doesn%27t%20work%20try%20%2Fusr%2Fsbin%2Fshibd%20-f%0D%0A%0D%0A%0D%0AIf%20you%20are%20going%20to%20use%20different%20commands%20to%20start%20shibd%20ensure%20that%20multiple%20copies%20are%20not%20running%20by%20do&amp;short_link=&amp;shortener=none&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=3&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-diigo">
			<a href="http://www.shareaholic.com/api/share/?title=Testing+Shibboleth+SP+2+on+CentOS+to+the+ukfederation+w%2F+Godaddy+certs&amp;link=http://mclear.co.uk/2009/10/27/testing-shibboleth-sp-2-on-centos-to-the-ukfederation-w-godaddy-certs/&amp;notes=Part%204.%20Testing%20%282%20hours%29%0D%0A%0D%0A%0D%0AShibboleth%20can%20be%20started%20using%20%2Fsbin%2Fservice%20shibd%20start%0D%0AAnother%20option%20is%20to%20use%3A%20service%20shibd%20restart%0D%0AIf%20the%20above%20doesn%27t%20work%20try%20%2Fusr%2Fsbin%2Fshibd%20-f%0D%0A%0D%0A%0D%0AIf%20you%20are%20going%20to%20use%20different%20commands%20to%20start%20shibd%20ensure%20that%20multiple%20copies%20are%20not%20running%20by%20do&amp;short_link=&amp;shortener=none&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=24&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Post this on Diigo">Post this on Diigo</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.shareaholic.com/api/share/?title=Testing+Shibboleth+SP+2+on+CentOS+to+the+ukfederation+w%2F+Godaddy+certs&amp;link=http://mclear.co.uk/2009/10/27/testing-shibboleth-sp-2-on-centos-to-the-ukfederation-w-godaddy-certs/&amp;notes=Part%204.%20Testing%20%282%20hours%29%0D%0A%0D%0A%0D%0AShibboleth%20can%20be%20started%20using%20%2Fsbin%2Fservice%20shibd%20start%0D%0AAnother%20option%20is%20to%20use%3A%20service%20shibd%20restart%0D%0AIf%20the%20above%20doesn%27t%20work%20try%20%2Fusr%2Fsbin%2Fshibd%20-f%0D%0A%0D%0A%0D%0AIf%20you%20are%20going%20to%20use%20different%20commands%20to%20start%20shibd%20ensure%20that%20multiple%20copies%20are%20not%20running%20by%20do&amp;short_link=&amp;shortener=none&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=257&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-reddit">
			<a href="http://www.shareaholic.com/api/share/?title=Testing+Shibboleth+SP+2+on+CentOS+to+the+ukfederation+w%2F+Godaddy+certs&amp;link=http://mclear.co.uk/2009/10/27/testing-shibboleth-sp-2-on-centos-to-the-ukfederation-w-godaddy-certs/&amp;notes=Part%204.%20Testing%20%282%20hours%29%0D%0A%0D%0A%0D%0AShibboleth%20can%20be%20started%20using%20%2Fsbin%2Fservice%20shibd%20start%0D%0AAnother%20option%20is%20to%20use%3A%20service%20shibd%20restart%0D%0AIf%20the%20above%20doesn%27t%20work%20try%20%2Fusr%2Fsbin%2Fshibd%20-f%0D%0A%0D%0A%0D%0AIf%20you%20are%20going%20to%20use%20different%20commands%20to%20start%20shibd%20ensure%20that%20multiple%20copies%20are%20not%20running%20by%20do&amp;short_link=&amp;shortener=none&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=40&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.shareaholic.com/api/share/?title=Testing+Shibboleth+SP+2+on+CentOS+to+the+ukfederation+w%2F+Godaddy+certs&amp;link=http://mclear.co.uk/2009/10/27/testing-shibboleth-sp-2-on-centos-to-the-ukfederation-w-godaddy-certs/&amp;notes=Part%204.%20Testing%20%282%20hours%29%0D%0A%0D%0A%0D%0AShibboleth%20can%20be%20started%20using%20%2Fsbin%2Fservice%20shibd%20start%0D%0AAnother%20option%20is%20to%20use%3A%20service%20shibd%20restart%0D%0AIf%20the%20above%20doesn%27t%20work%20try%20%2Fusr%2Fsbin%2Fshibd%20-f%0D%0A%0D%0A%0D%0AIf%20you%20are%20going%20to%20use%20different%20commands%20to%20start%20shibd%20ensure%20that%20multiple%20copies%20are%20not%20running%20by%20do&amp;short_link=&amp;shortener=none&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=&amp;service=38&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-twitter">
			<a href="http://www.shareaholic.com/api/share/?title=Testing+Shibboleth+SP+2+on+CentOS+to+the+ukfederation+w%2F+Godaddy+certs&amp;link=http://mclear.co.uk/2009/10/27/testing-shibboleth-sp-2-on-centos-to-the-ukfederation-w-godaddy-certs/&amp;notes=Part%204.%20Testing%20%282%20hours%29%0D%0A%0D%0A%0D%0AShibboleth%20can%20be%20started%20using%20%2Fsbin%2Fservice%20shibd%20start%0D%0AAnother%20option%20is%20to%20use%3A%20service%20shibd%20restart%0D%0AIf%20the%20above%20doesn%27t%20work%20try%20%2Fusr%2Fsbin%2Fshibd%20-f%0D%0A%0D%0A%0D%0AIf%20you%20are%20going%20to%20use%20different%20commands%20to%20start%20shibd%20ensure%20that%20multiple%20copies%20are%20not%20running%20by%20do&amp;short_link=&amp;shortener=none&amp;shortener_key=&amp;v=1&amp;apitype=1&amp;apikey=8afa39428933be41f8afdb8ea21a495c&amp;source=Shareaholic&amp;template=%2524%257Btitle%257D%2B-%2B%2524%257Bshort_link%257D&amp;service=7&amp;tags=&amp;ctype=" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
</ul><div style="clear: both;"></div><div class="shr-getshr" style="visibility:hidden;font-size:10px !important"><a target="_blank" href="http://www.shareaholic.com/?src=pub">Get Shareaholic</a></div><div style="clear: both;"></div></div>

<h3>Related Posts</h3>
<ol>
		<li><a href="http://mclear.co.uk/2009/10/26/installing-shibboleth-sp-2-on-centos-to-the-ukfederation-w-godaddy-certs/" rel="bookmark">Installing Shibboleth SP 2 on CentOS to the ukfederation w/ Godaddy certs</a><!-- (29.3)--></li>
		<li><a href="http://mclear.co.uk/2009/10/27/configuring-shibboleth-sp-2-on-centos-to-the-ukfederation-w-godaddy-certs/" rel="bookmark">Configuring Shibboleth SP 2 on CentOS to the ukfederation w/ Godaddy certs</a><!-- (25.7)--></li>
		<li><a href="http://mclear.co.uk/2009/10/27/configuring-apache-for-shibboleth-on-centos-to-the-ukfederation-w-godaddy-certs/" rel="bookmark">Configuring Apache for Shibboleth on CentOS to the ukfederation w/ Godaddy certs</a><!-- (25.5)--></li>
	</ol>
]]></content:encoded>
			<wfw:commentRss>http://mclear.co.uk/2009/10/27/testing-shibboleth-sp-2-on-centos-to-the-ukfederation-w-godaddy-certs/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

