IdP 2.4 Cookie Handling Error
Paul Hethmon
paul.hethmon at clareitysecurity.com
Thu Jul 17 11:40:08 EDT 2014
On Jul 17, 2014, at 11:30 AM, Cantor, Scott <cantor.2 at osu.edu<mailto:cantor.2 at osu.edu>> wrote:
As far as I've ever been able to tell, my users weren't regularly seeing
the results of this, so I concluded that the case that caused it was some
kind of browser anomaly that didn't actually affect users. But of the two
outcomes, I would expect that being able to control this at the IdP is
much better than the random outcome you'd get from an application.
I think in our environment, the empty response sent to the SP just resulted in a new AuthnRequest. So perhaps to the user annoying, but they just logged in again. Now, they stop and read the message and make a phone call. I'm thinking of adding a js timer to the error page and redirecting after a few seconds to a default location. It won't get rid of any problem, but may stop the phone calls.
Paul
Paul Hethmon
Chief Software Architect
paul.hethmon at clareitysecurity.com<mailto:paul.hethmon at clareitysecurity.com>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20140717/009035ee/attachment.html
More information about the users
mailing list