IDP-2.4.0 & 3.1.1authentication request -Behavior for HTTP & HTTPS - Same browser

Cantor, Scott cantor.2 at osu.edu
Mon Nov 23 10:03:11 EST 2015


On 11/23/15, 8:28 AM, "users on behalf of Surinaidu Majji" <users-bounces at shibboleth.net on behalf of pioneer.suri at gmail.com> wrote:



>In the above scenario both the cases(HTTP and HTTPS) treated as different. Shibboleth-IDP(2.4.0) treated differently when browser sending authentication request. The same browser is sending authentication request 2 times with different tabs but IDP considered both are different users and gives login page.

The IdP doesn't even know, in general, what the original URL was. The determination of "new user" is solely up to the IdP and the access to the IdP would have been https with the same URL in both cases, I would assume. I don't see how it could behave the way you're suggesting.

>Here are my queries:
>1) May I know, On what basis shibboleth-IDP(3.1.1) treating as Same unlike shibboleth-IDP2.4.0?

I can't think of any other possibly outcome in general.

>2) Kindly suggest, How to achieve our requirement(HTTPS & HTTP different) with IDP-3.1.1

I would guess that you can't, but since I don't know how you managed it before, the answer is probably "the same weird way that accidentally caused that behavior".

-- Scott



More information about the users mailing list