Attempt to spoof header (Shib-Cookie-Name) was detected

Peter Schober peter.schober at univie.ac.at
Tue Oct 4 05:18:20 EDT 2016


* Peter Schober <peter.schober at univie.ac.at> [2016-10-04 11:14]:
> > >    <Location />
> > >        AuthType shibboleth
> > >        Require shibboleth
> > >        ShibRequestSetting applicationId default
> 
> The default applicationId is "default", so at best that does nothing.

Well, unless you have other config you didn't mention that uses
ApplicationOverride and sets the applicationId to a non-default value.
-peter


More information about the users mailing list