V2.4+ are NOT compatible with Windows 2003 Server RTM (without SP1). |
The installer does not work fully in conjunction with the IIS "Shared Configuration" option. Disable it prior to installation. After re-enabling it, you will likely have to manually apply some of the configuration changes noted below. |
.msi
Shibboleth SP installer from the Shibboleth download site.After rebooting, IIS should be configured for basic support (if you asked it to do so). If you have problems, need to manually configure it, or want to verify what happened, the IIS steps are as follows:
lib\shibboleth\isapi_shib.dll
library (orĀ lib64\shibboleth\isapi_shib.dll
for a 64-bit IIS). The priority should be High
. You won't see any visual indication it was loaded until after making requests to the server..sso
file extension to the ISAPI library so that virtual URLs can be specified to invoke the extension handler for each web site. On the Home Directory
tab, add a script mapping using the Configuration
button. The Executable
box should point to isapi_shib.dll
, and the "Extension" can be set to anything unlikely to conflict, but .sso
is assumed (and the dot must be included). You should NOT select the option to limit verbs, and you MUST uncheck the Check that file exists
box.shibd
, will be located at \etc\shibboleth\shibboleth2.xml
(within the directory used to install the SP software).shibd
creates its own log at \var\log\shibboleth\shibd.log
and must have appropriate read and write permissions itself for the entire installation directory.\var\log\shibboleth
to create the native.log
file.