Child pages
  • Shibbolizing Wiki

Versions Compared


  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: Migrated to Confluence 5.3
Table of Contents


This document covers how to Shibbolize the wiki.

Summary of Changed Files (for Confluence only)

Changed Files

Code Block

New Files

Code Block

Install Shibboleth

See Setting up a Shibboleth SP for setting up Shibboleth itself.

Apache Config Changes

The mod_proxy settings have to be altered to not proxy shibd stuff. So, in ssl.conf (not 100% sure where this is located on prod), add the following before the first ProxyPass directive:

Code Block
ProxyPassMatch ^(/Shibboleth) !
ProxyPassMatch ^(/shibboleth) !
ProxyPassMatch ^(/shibboleth-sp) !

Then change the ProxyPass* directives to the following:

Code Block
ProxyPass / ajp://localhost:8009/
ProxyPassReverse / ajp://localhost:8009/

Also, at the top of the vhost section in ssl.conf, remove the :443 from the server name.

Install Confluence Shibboleth Plugin

Copy the plugin from wiki-dev. This jar is located at:

Code Block

Put it in the same place on production.

Copy the plugin properties file from wiki-dev. This file is located at:

Code Block

Put this in the same place on production, as well.

Confluence (Tomcat) Config Changes

server.xml Changes

In /web/confluence-3.3.3-std/conf/server.xml set up a new Connector on port 8009 which uses AJP:

Code Block
<Connector port="8009" protocol="AJP/1.3"
      minSpareThreads="5" maxThreads="256"
      scheme="https" proxyPort="443" tomcatAuthentication="false" />

seraph-config.xml Changes

In /web/confluence-3.3.3-std/confluence/WEB-INF/classes/seraph-config.xml make the following changes:

Code Block
      <!-- <param-value>/login.action?os_destination=${originalurl}</param-value> -->
      <!-- <param-value>/login.action</param-value> -->
<!-- <authenticator class="com.atlassian.confluence.user.ConfluenceAuthenticator"/> -->
<authenticator class="shibauth.confluence.authentication.shibboleth.RemoteUserAuthenticator"/>

Convert Usernames