From CSCWiki
Revision as of 02:38, 29 December 2021 by Merenber (talk | contribs)
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to navigation Jump to search

Starting from July 2021, we are a registered SAML SP (Service Provider) for the University of Waterloo's ADFS system.

Our metadata URL is

Our SP certificate is currently set to expire in July 2031; make sure to renew it before then.

The ADFS IdP metadata XML (from the university) is set to expire in October 2025; make sure to download a new copy before then.


Unfortunately the form which we need to submit to IST to become a SP can only be accessed by faculty, so ask our club advisor to submit it for us (as of this writing, that is Dr. Prabhakar Ragde). IST may be slow to respond, so make sure to do this well before our certificate expires.

Here's some information which you'll need for the form:

Apache setup

These steps are adapted from
Also see

Install the mod_auth_mellon module:

apt install libapache2-mod-auth-mellon

Create a keypair and XML file:


Place the files under /etc/apache2/saml on caffeine (make sure the private key is only readable by root), and store a copy under /home/sysadmin/certs/ on xylitol.

Also download a copy of the ADFS IdP metadata XML file:

wget -O /etc/apache2/saml/FederationMetadata.xml

Enable the Mellon module:

a2enmod auth_mellon

Add the following snippet to /etc/apache2/sites-real/csc on caffeine:

    <Location / >
      MellonEnable info
      MellonEndpointPath /saml
      MellonSPMetadataFile /etc/apache2/saml/
      MellonSPPrivateKeyFile /etc/apache2/saml/
      MellonSPCertFile /etc/apache2/saml/
      MellonIdPMetadataFile /etc/apache2/saml/FederationMetadata.xml
      MellonSecureCookie On
      MellonRedirectDomains *
      MellonMergeEnvVars On
      MellonSetEnvNoPrefix REMOTE_USER NAME_ID
      MellonSetEnvNoPrefix ADFS_GROUP

Now restart (or reload if the Mellon module is already loaded):

systemctl restart apache2


To make sure that everything is working, paste the following into /srv/saml-test/index.php on caffeine:

header('Content-Type: text/plain');

foreach($_SERVER as $key=>$value) {
    if(substr($key, 0, 7) == 'MELLON_' || substr($key, 0, 5) == 'ADFS_') {
          echo($key . '=' . $value . "\r\n");

Now add the following snippet to /etc/apache2/sites-real/csc:

    Alias /saml-test /srv/saml-test
    <Location /saml-test >
      AuthType Mellon
      MellonEnable auth
      Require valid-user

Now if you visit, you should get redirected to ADFS.

Known limitations

It is not currently possible to use any of the Mellon* directives in a .htaccess file. Here is the open GitHub issue for it (if it is now closed, please update this wiki page).


If you want to view the certificate information inside one of the metadata XML files, you can actually just copy the value inside the <X509Certificate> tag, then place it between PEM headers like this:


Now you can use openssl to analyze it:

openssl x509 -noout -text -in metadata.pem