Fwd: Why Shibboleth SET a cookie to a browser and Shibboleth multi domain support

Michael Furman furman.michael at gmail.com
Tue Aug 16 04:21:48 BST 2011


Hi all!

I am new to Shibboleth but definitely not new for the security :)

I want to clarify couple of issues:



1) According to my understanding the SAML protocol does not define how the
information from the assertion is added to a browser.

I have looked into Shibboleth demo:

http://www.switch.ch/aai/demo/expert.html



 I see that a cookie was added when the resource is finally accessed:

Set-Cookie: _shibsession_default=b03871b42d188af4062e6fbd777550ad; path=/



So, please clarify me if Set-Cookie is part of SAML2 protocol or it is
addition of Shibboleth to set the state of SAML2 authentication in a
browser.



2) What happens if my application accesses other DNS domain?

According to my knowledge a browser will not send a cookie.

How Shibboleth solves this problem?



Thank you in advance for the clarifications!

Best regards,

  Michael
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20110816/8f1e4eeb/attachment.html 


More information about the users mailing list