# ADD THIS TO THE END OF YOUR APACHE'S HTTPD.CONF

######
## SHIB Config
######

#
# Load the Resource Manager and SHIRE modules.
# Note that ORDER MATTERS!  Apache runs the modules in the
# _reverse_ order that modules were loaded.  The RM module
# depends on the Shire module, so you need this load-order
# to make sure they are run properly.
#
# If you see log messages about "NOOP" configurations, then you
# have messed this up.
#
LoadModule shibrm_module /opt/shibboleth/libexec/mod_shibrm.so
LoadModule shire_module /opt/shibboleth/libexec/mod_shire.so

#
# Global SHIRE Configuration
# This is the INI file that contains all the global, non-apache-specific
# configuration.  Look at this file for most of your configuration
# parameters.
#
SHIREConfig /opt/shibboleth/etc/shibboleth/shibboleth.ini

#
# The SHIRE POST processor URL
# Most of the time, this should be a path only, so that the schema,
# host, and port will determined dynamically in each virtual host.  If
# for some reason the dynamically derived URL is not appropriate, a
# complete URL can be used, and may be set per-vhost explicitly:
# SHIREURL https://<server-name>/SHIRE
#
# The SHIREURL and subsequent "Location" handler must match.
#
SHIREURL /SHIRE
<Location /SHIRE>
  SetHandler shib-shire-post
</Location>

#
# Configure a test directory
#
# You need _at least_ a "require" option for Shib to take effect for this
# directory.  You can either set the AuthType to "shibboleth", or you can
# turn on ShibBasicHijack. For Shib, valid-user is a somewhat vague concept
# and only means that a trusted origin site has authenticated the user, but
# doesn't mean that any attributes were received.
#
<Location /secure>
  AuthType shibboleth
  require affiliation ~ ^member@.+$
  # require valid-user

  # Per-directory SHIRE Configuration
  #ShibBasicHijack On
  #ShibSSLOnly On
  #ShibAuthLifetime 14400
  #ShibAuthTimeout 3600

  # RM Configuration
  #AuthGroupFile /foo
  #ShibExportAssertion On
</Location>
