You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在Windows 2008 R2+IIS环境下获取Shibboleth Header及CGI变量

如何访问Shibboleth属性以实现应用登录或基于属性创建用户?

环境信息

  • 服务器:Windows 2008 R2 64位
  • 应用:Coldfusion 10
  • 已部署组件:Shibboleth Service Provider(SP) 3.4 + IIS 7.5.7
  • Shibboleth状态:已启用useHeaders,允许Shibboleth Web扩展的ISAPI和CGI限制;状态检查正常,可通过Identity Provider(IDP)成功认证,SP会话中能看到IDP释放的eppn、mail、sn、givenName属性

部分Shibboleth配置片段

<InProcess>
        <ISAPI normalizeRequest="true" safeHeaderNames="true" useHeaders="true">
            
            <Site id="3" name="coursestest.cit.ie" scheme="https" port="443"/>
            
        </ISAPI>
</InProcess>
...
<ApplicationDefaults entityID="https://country.com/shibboleth"
        REMOTE_USER="eppn subject-id pairwise-id persistent-id"
        attributePrefix="HTTP_"
        homeURL="/name/index.cfm?action=checkLogin"
        cipherSuites="DEFAULT:!EXP:!LOW:!aNULL:!eNULL:!DES:!IDEA:!SEED:!RC4:!3DES:!kRSA:!SSLv2:!SSLv3:!TLSv1:!TLSv1.1">

遇到的问题

使用cfdump getHTTPRequestData()和cfdump CGI均返回空值,调用getHTTPRequestData().headers['http_mail']也无法获取到IDP释放的mail属性(已在配置中添加HTTP前缀)。

期望实现的逻辑

<cfset reqHeaders = getHTTPRequestData()>
<cfif reqHeaders.headers.http_eppn NEQ "">
   <cfset fedVars.lastname = CGI.sn>
   <cfset fedVars.firstname = CGI.givenName>
<cfset fedVars.email = CGI.mail>
<cfelse>
   <cfexit>
</cfif>

解决方法

  1. 检查IIS请求筛选器设置

    • 打开IIS管理器,进入对应站点的「请求筛选」→「HTTP头」标签,确保未阻止Shibboleth传递的HTTP头(如HTTP_eppn、HTTP_mail等),若有拦截规则需将这些头添加至允许列表。
  2. 调整ColdFusion的HTTP头处理配置

    • ColdFusion 10默认可能不暴露所有自定义HTTP头到CGI作用域或getHTTPRequestData()中,需修改cfusion\runtime\conf\server.xml的<Connector>节点,添加相关配置后重启ColdFusion服务:
      <Connector port="8500" protocol="HTTP/1.1"
                 connectionTimeout="20000"
                 redirectPort="8443"
                 useBodyEncodingForURI="true"
                 tomcatAuthentication="false"
                 proxyName="coursestest.cit.ie"
                 proxyPort="443"
                 scheme="https"/>
      
  3. 修改Shibboleth的safeHeaderNames配置

    • 当前safeHeaderNames="true"会将属性名转换为符合HTTP规范的格式(如givenName转为HTTP_GIVEN_NAME),可尝试将该值改为false,或在ColdFusion中使用转换后的头名称(如HTTP_GIVEN_NAME而非http_givenName),修改后重启Shibboleth服务。
  4. 改用CGI变量传递属性

    • 关闭Shibboleth的useHeaders,改用CGI变量传递属性。修改ISAPI节点的useHeaders="false",同时将ApplicationDefaults中的attributePrefix改为CGI_:
      <ISAPI normalizeRequest="true" safeHeaderNames="true" useHeaders="false">
      ...
      <ApplicationDefaults ... attributePrefix="CGI_" ...>
      
    • 之后在ColdFusion中通过CGI.CGI_eppn、CGI.CGI_mail等变量获取属性值。
  5. 验证属性映射规则

    • 确认Shibboleth的attribute-map.xml已正确配置IDP释放属性到SP的映射,示例如下:
      <Attribute name="urn:oid:0.9.2342.19200300.100.1.3" id="mail"/>
      <Attribute name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" id="eppn"/>
      <Attribute name="urn:oid:2.5.4.4" id="sn"/>
      <Attribute name="urn:oid:2.5.4.42" id="givenName"/>
      
    • 确保映射规则无错误,否则SP无法正确解析IDP释放的属性。

内容的提问来源于stack exchange,提问作者Ismail Hossain

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.26 19:53:14