Recent Safari update breaks some SPs ?

Michael A Grady mgrady at unicon.net
Wed Oct 26 13:37:43 EDT 2016


> On Oct 26, 2016, at 12:12 PM, Cantor, Scott <cantor.2 at OSU.EDU> wrote:
> 
>> But I'd also note that if it is a Safari problem, I think it would actually only
>> break things and cause a problem for SPs that are *signing* AuthnRequests
>> using the Redirect binding.  That's not the norm, and so that is likely not a
>> huge pool of problem candidates to start out with.  And then: not all Mac
>> users use Safari; not all users have upgraded yet; etc.  So I wouldn't rule out
>> Safari as the culprit just yet, based on lack of reports.
> 
> Other caveats: you'd need relay state containing actual URLs needing safe encoding to actually spot that kind of thing in the logs (Shibboleth SPs don't do that by default, and many other SPs don't either).
> 
> -- Scott
> 

So not apples-to-apples, but I have an SP sending Authn Requests to SimpleSAMLphp where it's using Redirect with a signature and a RelayState that is URL encoded. (But not strictly a URL, as it starts:
      RelayState=something%3A%2F%2Fhttps%3A%2F%2Flogin  )

Using the latest Safari, that still works fine.

--
Michael A. Grady
IAM Architect, Unicon, Inc.

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 842 bytes
Desc: Message signed with OpenPGP using GPGMail
URL: <http://shibboleth.net/pipermail/users/attachments/20161026/698b25d5/attachment.sig>


More information about the users mailing list