Issue with large HTTP headers for ECP authentication

Cantor, Scott cantor.2 at osu.edu
Tue Dec 11 18:35:35 EST 2018


On 12/11/18, 5:28 PM, "users on behalf of Daudt, Carl" <users-bounces at shibboleth.net on behalf of crdaudt at taylor.edu> wrote:

> We determined that with our ECP connections, the shib_idp_session_ss cookie was being populated with all of the LDAP
> fields available to the LDAP data connector.

Not at all, this has nothing to do with data connectors. Authentication is distinct, no overlap whatsoever (unless you run the resolver yourself during MFA logic or something of that sort).

I hadn't realized the LDAP authentication results included the attributes returned during authentication, hadn't considered that possibility. But even if it does, why would that bloat the cookies? They'd have some fixed size increase of course, but it wouldn't grow over time.

I'm not sure why you'd need to return any attributes during authentication at all. Normally authentication operates on the value the user enters once it's validated as "correct".

-- Scott




More information about the users mailing list