SSO Redirect Loop

Tim Owens tim at reclaimhosting.com
Tue Aug 23 11:14:12 EDT 2016


Well I'm glad to hear it's not certificate-related. To be honest not sure
why I assumed it could be other than that perhaps our SP wasn't able to
decode the response from the IdP, but even as I type that I realize since
the shib session gets set it is getting a proper response so that wouldn't
even make sense.

I've monitored headers at every aspect of the loop and see it sending the
cookie and all the URLs match up so it doesn't appear to be an issue of URL
mismatch. Are there other scenarios that would cause this? Local logins
work fine so I know the app is capable of setting cookies for logged in
users and we've used the Shibboleth plugin successfully in the past and not
run into this previously so it's a bit of a headscratcher for me.

Tim Owens
Co-Founder • tim at reclaimhosting.com


On Tue, Aug 23, 2016 at 10:28 AM, Cantor, Scott <cantor.2 at osu.edu> wrote:

> On 8/23/16 10:15 AM, Tim Owens wrote:
> >
> > When I looked over the information in the wiki related to redirect loops
> > it mentioned making sure SSL was enabled across the app and forced when
> > using cookieprops=https and that has already been done.
>
> It remains the case that your cookies are at fault. That is always the
> cause of a loop. Session issued, cookie set, cookie not returned, loop.
>
> > Would this have
> > something to do with the certificate being used by shibd?
>
> Nope. I would be fascinated to understand why people always assume that.
> We probably should edit the page and just say in red "this is not a
> certificate issue".
>
> -- Scott
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160823/543014a7/attachment.html>


More information about the users mailing list