Fwd: Why Shibboleth SET a cookie to a browser and Shibboleth multi domain support
Michael Furman
furman.michael at gmail.com
Tue Aug 16 04:21:48 BST 2011
Hi all!
I am new to Shibboleth but definitely not new for the security :)
I want to clarify couple of issues:
1) According to my understanding the SAML protocol does not define how the
information from the assertion is added to a browser.
I have looked into Shibboleth demo:
http://www.switch.ch/aai/demo/expert.html
I see that a cookie was added when the resource is finally accessed:
Set-Cookie: _shibsession_default=b03871b42d188af4062e6fbd777550ad; path=/
So, please clarify me if Set-Cookie is part of SAML2 protocol or it is
addition of Shibboleth to set the state of SAML2 authentication in a
browser.
2) What happens if my application accesses other DNS domain?
According to my knowledge a browser will not send a cookie.
How Shibboleth solves this problem?
Thank you in advance for the clarifications!
Best regards,
Michael
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20110816/8f1e4eeb/attachment.html
More information about the users
mailing list