SSO Redirect Loop
Tim Owens
tim at reclaimhosting.com
Tue Aug 23 10:15:41 EDT 2016
We have an SP setup at https://createunl.com (a WordPress installation). We
modified .htaccess to allow /Shibboleth.sso requests to get passed to the
shibd process. The application is properly directing users to the IdP but
when they're sent back the browser starts looping through additional
https://shib.unl.edu/idp/profile/SAML2/Redirect/SSO?SAMLRequest pages.
The transaction log shows successful authentication and
/Shibboleth.sso/Session shows a proper session exists so I'm assuming for
some reason the app isn't getting a cookie stored correctly.
When I looked over the information in the wiki related to redirect loops it
mentioned making sure SSL was enabled across the app and forced when using
cookieprops=https and that has already been done. Would this have something
to do with the certificate being used by shibd? It's currently just a
self-signed hostname certificate, does it need to match the endpoint? Or am
I on the wrong trail?
Tim Owens
Co-Founder • tim at reclaimhosting.com
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160823/ea160d45/attachment.html>
More information about the users
mailing list