Request header cookie exceeds server limit with relayState="ss:mem"

Jeremy Shapiro jnshapiro at gmail.com
Thu Mar 3 23:29:16 EST 2016


We are using the postData Sessions element so I would expect that cookie to
appear.  And I see now that my relayState ss:mem is being overridden by the
SessionInitiator element so I'd expect both shibpost and shibstate.  Based
on what you've said the increasing cookie count also makes sense with my
testing.  If I hit the sp, get redirected to login, but then go back to the
sp again without logging in, and repeat that cycle, my cookie count is
going to increase.

I can limit shibstate with the relay state suffix option.  But is there a
way to limit the shibpost cookie count?

  Jeremy

On Thu, Feb 18, 2016 at 4:32 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:

> > I'm unable to reproduce the problem of the number of cookies increasing.
> > With a new session,  I now get three cookies _shibpost, _shibstate, and
> > _shibsession.  Are you saying that's unexpected as well?
>
> Yes. That certainly isn't relayState by way of the storage service, that
> would be using the "cookie" option (that's what the "state" one is from).
> So seems like that disconnect is a place to start.
>
> The _shibpost cookie should only be set if the initial request is via POST
> and the option to preserve POST data is set (you didn't say). And it should
> get cleaned up after sign-on when it ends up "replaying" the form POST.
>
> -- Scott
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160303/fb1c7f38/attachment.html>


More information about the users mailing list