Information included on this page will help you to install and use Shibboleth for authentication and integration with OnePass on an Linux or Windows or other servers.
**The configuration below is for your reference only. Some parameters and paths may be different with different Shibboleth versions / sub-versions. Kindly double-check the corresponding path name/certificate name in your configuration file.
| ApplicationDefaults, update entityID=”sp.example.org” to your application hostname, change REMOTE_USER=”NameID”, add signingAlg=”http://www.w3.org/2001/04/xmldsig-more#rsa-sha256″ digestAlg=”SHA256″ e.g. <ApplicationDefaults entityID=”https://abc.cuhk.edu.hk/shibboleth” REMOTE_USER=”eppn persistent-id NameID” signingAlg=”http://www.w3.org/2001/04/xmldsig-more#rsa-sha256″ digestAlg=”SHA256″> |
| Sessions lifetime: update to “28800”, timeout: update to “1200” |
| SSO entityID, should be updated to OnePass entityID, the entityIDs for UAT / production environments are provided by OnePass support. |
| Handle type: update to “MetadataGenerator”, signing: update to “true” |
| Errors supportContact: update to a valid email address for the person managing the SP configuration |
| MetadataProvider type: update the url to OnePass UAT / Production environments which will be provided by OnePass Support. |
For more information about the specifics of the attributes released, please contact ITSC Service Desk.
