Apache set headers for /Shibboleth.sso

Cantor, Scott cantor.2 at osu.edu
Wed Jan 23 09:23:15 EST 2019


On 1/23/19, 9:14 AM, "users on behalf of Cantor, Scott" <users-bounces at shibboleth.net on behalf of cantor.2 at osu.edu> wrote:

> However, this [1] would suggest that the example is just wrong. I don't like removing contributed docs, but since this
> one appears not to work I will probably add a warning to it.

I will say that looking at it briefly would suggest you're not doing this right. There's no reason the SP should be redirecting to /Shibboleth.sso/Login. That's only done if an application is configured to deliberately use that endpoint via redirect. Ordinary configuration of a protected resource to require a session would automatically respond with the SAML request, and if that's a form response for the POST binding, that would be the response. You've deliberately subverted that somewhere.

-- Scott




More information about the users mailing list