idp.cookie.secure Ignored?

Jason Rotunno jrotunno at swarthmore.edu
Wed Jun 12 18:24:00 EDT 2019


On Wed, Jun 12, 2019 at 5:30 PM Cantor, Scott <cantor.2 at osu.edu> wrote:

> > But after restarting Shib the Secure flag is still being used. Is this a
> bug (I
> > searched for a bug related to this but didn't find anything), or am I
> just missing
> > something?
>
> Any cookies the IdP sets are governed by it, others are not and would be
> controlled in whatever way governs them.
>
> -- Scott
>

These would be cookies set by the IdP; for example (this is after changing
idp.cookie.secure to false):

HTTP/1.1 302
Set-Cookie: JSESSIONID=8D9E91ADF81898B4299A59E6703DE060; Path=/idp; Secure;
HttpOnly
Cache-Control: no-store
X-Frame-Options: DENY
Strict-Transport-Security: max-age=0
Content-Security-Policy: frame-ancestors 'none';
Location: /idp/profile/cas/login?execution=e1s1
Content-Length: 0
Date: Wed, 12 Jun 2019 19:20:14 GMT
Connection: close


I ended up finding a thread where someone else was having the same problem
and you mentioned that web.xml has its own settings (
http://shibboleth.1660669.n2.nabble.com/NoSuchFlowExecutionException-e1s1-td7642152.html).
Does that mean that the latter overrides the former?

-- 

Jason Rotunno
System & Security Administrator
Swarthmore College
500 College Ave
Swarthmore, PA 19081
610.328.8505

Think BEFORE You Click!! Emails from Swarthmore College ITS won't be in your
Quarantine or Spam folder. We won't threaten you either! If you
receive any phishing emails, please forward them to phishing at swarthmore.edu.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20190612/1fe2de4f/attachment.html>


More information about the users mailing list