Sign inSign up

mans0954/tier-idp

By mans0954

•Updated over 8 years ago

Unofficial fork of the Internet2 Shibboleth IdP image

Image
0

427

mans0954/tier-idp repository overview

⁠Shibboleth IDP

Unofficial Docker container for the Shibboleth IdP. Derived from https://github.com/Internet2/tier-idp⁠

For official information about Shibboleth, please see:

http://shibboleth.net/⁠

Shibboleth is Copyright University Corporation for Advanced Internet Development, Inc. (Internet2) and distributed under the Apache 2.0 license.

The files in this project is based on https://github.com/Internet2/tier-idp/⁠ Original Copyright and License unknown, Modifications Copyright Christopher Hoskin. Original Maintainer Mark McCahill "[email protected]⁠"

THIS CONTAINER IS PURELY FOR DEMONSTRATION PURPOSES ON YOUR LOCALHOST. IT IS NOT PRODUCTION READY.

In particular, I have done several things which would be completely inappropriate for anything which could be accessed by third parites. A non-exhaustive list is:

  • Used http rather than https endpoints
  • Allowed the IdP to respond to unverified relying parties
  • Used weak default passwords
  • Not using a service principal for communication with the KDC
  • Using cookieProps="http" rather than cookieProps="https"

⁠Components

⁠Building

docker-compose build

⁠Running

docker-compose up

⁠Testing

Browse to http://test-sp.docker/secure/⁠ and log in with the username user1 and password password1.

⁠How to verify the IDP from inside the container

0.) run an instance

   ./run

1.) find the id for the docker instance

$ sudo docker ps
CONTAINER ID        IMAGE               COMMAND             CREATED              STATUS              PORTS                                               NAMES
c6bb80bf3ce2        shibboleth-idp      "/usr/sbin/init"    About a minute ago   Up About a minute   80/tcp, 443/tcp, 8443/tcp, 0.0.0.0:8080->8080/tcp   tiny_ramanujan

2.) use the docker exec command to start a bash shell and then use curl to ask for status:

$ sudo docker exec -it c6bb80bf3ce2 bash
[root@c6bb80bf3ce2 /]# curl http://localhost:8080/idp/status
### Operating Environment Information
operating_system: Linux
operating_system_version: 3.13.0-85-generic
operating_system_architecture: amd64
jdk_version: 1.8.0_77
available_cores: 4
used_memory: 1056 MB
maximum_memory: 3566 MB

### Identity Provider Information
idp_version: 3.2.1
start_time: 2016-04-07T21:54:16Z
current_time: 2016-04-07T21:55:21Z
uptime: 64967 ms

service: shibboleth.LoggingService
last successful reload attempt: 2016-04-07T21:53:57Z
last reload attempt: 2016-04-07T21:53:57Z

service: shibboleth.ReloadableAccessControlService
last successful reload attempt: 2016-04-07T21:53:59Z
last reload attempt: 2016-04-07T21:53:59Z

service: shibboleth.MetadataResolverService
last successful reload attempt: 2016-04-07T21:53:59Z
last reload attempt: 2016-04-07T21:53:59Z

	metadata source: ShibbolethMetadata

service: shibboleth.RelyingPartyResolverService
last successful reload attempt: 2016-04-07T21:53:58Z
last reload attempt: 2016-04-07T21:53:58Z

service: shibboleth.NameIdentifierGenerationService
last successful reload attempt: 2016-04-07T21:53:58Z
last reload attempt: 2016-04-07T21:53:58Z

service: shibboleth.AttributeResolverService
last successful reload attempt: 2016-04-07T21:53:58Z
last reload attempt: 2016-04-07T21:53:58Z

	DataConnector staticAttributes: has never failed

service: shibboleth.AttributeFilterService
last successful reload attempt: 2016-04-07T21:53:58Z
last reload attempt: 2016-04-07T21:53:58Z

[root@c6bb80bf3ce2 /]# 

Tag summary

Content type

Image

Digest

Size

308.9 MB

Last updated

over 8 years ago

docker pull mans0954/tier-idp