session initiator / wayf question

Cantor, Scott cantor.2 at osu.edu
Sun Oct 26 15:28:01 EDT 2014


On 10/26/14, 2:44 PM, "Mike Flynn" <shibbolethlynda at yahoo.com> wrote:

>Here is one:
>
>ProQuest
> - Sign In 
><https://shib.lynda.com/Shibboleth.sso/InCommon?providerId=https://www.okt
>a.com/kn2f4wn9UYYBSSGGIHDI&target=https://shib.lynda.com/InCommon>

The protected resource is https://shib.lynda.com/InCommon, so when they
get back to that spot after the POST, they're not sending the cookie back
or it's not usable.

Note that you are preventing anybody from using SAML 2 if it falls into
the discovery step. It's using the old WAYF handoff that only works with
legacy Shibboleth protocol.

-- Scott



More information about the users mailing list