idp.cookie.secure Ignored?

Jason Rotunno jrotunno at swarthmore.edu
Wed Jun 12 16:22:16 EDT 2019


Hi All,

I'm playing with SSL offloading so that traffic is decrypted before being
sent to a test Shibboleth instance I setup (v3.4.0). This means I need to
disable the Secure flag with cookies. I modified conf/idp.properties to:

idp.cookie.secure = false


But after restarting Shib the Secure flag is still being used. Is this a
bug (I searched for a bug related to this but didn't find anything), or am
I just missing something?

Thanks,
Jason

-- 

Jason Rotunno
System & Security Administrator
Swarthmore College
500 College Ave
Swarthmore, PA 19081
610.328.8505

Think BEFORE You Click!! Emails from Swarthmore College ITS won't be in your
Quarantine or Spam folder. We won't threaten you either! If you
receive any phishing emails, please forward them to phishing at swarthmore.edu.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20190612/8c574631/attachment.html>


More information about the users mailing list