You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Apache与mod_auth_mellon集成SAML遇阻,请求技术排查建议

Apache mod_auth_mellon SAML配置问题排查求助

问题概述

我正在搭建Apache与Mellon SAML模块的测试环境,配置参考官方文档,仅将基础域名改为jlfoo.com,目标是保护/private路径。测试时未跳转至登录页,直接显示“Unauthorized”页面。

错误日志

日志a

[Mon Mar 17 09:36:40.822699 2025] [auth_mellon:error] [pid 15715:tid 15795] [client 100.36.177.53:55700] Error processing authn response. Lasso error: [-432] Status code is not success, SAML Response: StatusCode1="urn:oasis:names:tc:SAML:2.0:status:Requester", StatusCode2="urn:oasis:names:tc:SAML:2.0:status:InvalidNameIDPolicy", StatusMessage="(null)", referer: https://idcs-697d8bc1d228424cb0f6b7b9fa1f015a.identity.oraclecloud.com/

日志b

[Mon Mar 17 09:37:16.194532 2025] [auth_mellon:error] [pid 15715:tid 15785] [client 100.36.177.53:55710] Endpoint "index.html" not handled by mod_auth_mellon.

配置文件(mellon.conf,已引入Apache httpd.conf)

<Location / >
    MellonEnable info
    MellonEndpointPath /mellon/
    MellonSPMetadataFile /apps/httpd2.4/conf/mellon/https_apachesaml01.jlfoo.com_mellon_metadata.xml
    MellonSPPrivateKeyFile /apps/httpd2.4/conf/mellon/https_apachesaml01.jlfoo.com_mellon_metadata.key
    MellonSPCertFile /apps/httpd2.4/conf/mellon/https_apachesaml01.jlfoo.com_mellon_metadata.cert
    MellonIdPMetadataFile /apps/httpd2.4/conf/mellon/IDCSMetadata.xml
    MellonIdPPublicKeyFile /apps/httpd2.4/conf/mellon/IDCSCertificate.pem
</Location>

<Location /private >
    AuthType Mellon
    MellonEnable auth
    Require valid-user
</Location>

SP元数据(Apache/Mellon侧)

<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<EntityDescriptor xmlns="urn:oasis:names:tc:SAML:2.0:metadata" entityID="https://apachesaml01.jlfoo.com/mellon/metadata">
      <SPSSODescriptor AuthnRequestsSigned="true" WantAssertionsSigned="true" protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
        <KeyDescriptor use="signing">
      <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
        <ds:X509Data>
                          <ds:X509Certificate>MIICyTCCAbECFGiWScEOgKh+SolrnpiaYfk9H5ieMA0GCSqGSIb3DQEBCwUAMCEx
    HzAdBgNVBAMMFmFwYWNoZXNhbWwwMS5qbGZvby5jb20wHhcNMjUwMzE3MTAxNDM1
    WhcNMzUwMzE3MTAxNDM1WjAhMR8wHQYDVQQDDBZhcGFjaGVzYW1sMDEuamxmb28u
    Y29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqaYgpwZBYhCYFCnT
    .
    .
    .
    LH0fnonONikLaVqxrBcmlG0VBuxSEN/QC7C
    /pc9Z4sB2FoeGLjviz3zOW/iIndy+Q9Nr5uRphSvq0k7oBGhfnqMArM/xgoHh6vl
    Vzm4HrJPZrpEwHrmbKXi3Zq+wzTF1GIKS0pPAtSiw2xbWmJJUWAZXs+zIdvZ</ds:X509Certificate>
            </ds:X509Data>
          </ds:KeyInfo>
        </KeyDescriptor>
        <KeyDescriptor use="encryption">
          <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
            <ds:X509Data>
              <ds:X509Certificate>MIICyTCCAbECFGiWScEOgKh+SolrnpiaYfk9H5ieMA0GCSqGSIb3DQEBCwUAMCEx
    HzAdBgNVBAMMFmFwYWNoZXNhbWwwMS5qbGZvby5jb20wHhcNMjUwMzE3MTAxNDM1
    WhcNMzUwMzE3MTAxNDM1WjAhMR8wHQYDVQQDDBZhcGFjaGVzYW1sMDEuamxmb28u
    .
    .
    .
    NwtYvkiZzmCV85Mufiz/APZMCfxmp26be+4o8Tiy5tFN+Ii822hpB2
    TPelL/jw6KI5AgYpTyEdyUML/F6emLH0fnonONikLaVqxrBcmlG0VBuxSEN/QC7C
    /pc9Z4sB2FoeGLjviz3zOW/iIndy+Q9Nr5uRphSvq0k7oBGhfnqMArM/xgoHh6vl
    Vzm4HrJPZrpEwHrmbKXi3Zq+wzTF1GIKS0pPAtSiw2xbWmJJUWAZXs+zIdvZ</ds:X509Certificate>
        </ds:X509Data>
      </ds:KeyInfo>
    </KeyDescriptor>
    <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://apachesaml01.jlfoo.com:18443/mellon/logout"/>
    <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://apachesaml01.jlfoo.com:18443/mellon/logout"/>
    <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:userID</NameIDFormat>
    <AssertionConsumerService index="0" isDefault="true" Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://apachesaml01.jlfoo.com:18443/mellon/postResponse"/>
    <AssertionConsumerService index="1" Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://apachesaml01.jlfoo.com:18443/mellon/artifactResponse"/>
    <AssertionConsumerService index="2" Binding="urn:oasis:names:tc:SAML:2.0:bindings:PAOS" Location="https://apachesaml01.jlfoo.com:18443/mellon/paosResponse"/>
      </SPSSODescriptor>
    </EntityDescriptor>

求助需求

已知mod_auth_mellon已停止维护,希望熟悉该模块的人士提供排查方向。


内容的提问来源于stack exchange,提问作者jstack100

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 21:24:54