idp.cookie.secure Ignored?

Jason Rotunno jrotunno at swarthmore.edu
Thu Jun 13 08:16:47 EDT 2019


Got it. Thanks, Rod.

Jason


On Thu, Jun 13, 2019 at 5:30 AM Rod Widdowson <rdw at steadingsoftware.com>
wrote:

> Scott:
>
> >> Any cookies the IdP sets are governed by it, others are not and would
> be controlled in whatever way governs them.
>
> > Set-Cookie: JSESSIONID=8D9E91ADF81898B4299A59E6703DE060; Path=/idp;
> Secure; HttpOnly
>
> The point here is that the IdP doesn’t set JSESSIONID, that’s the
> container.  Controlling how the container works is outwith IdP
> configuration so you should use the canonical method...
>
> R
>
> --
> For Consortium Member technical support, see
> https://wiki.shibboleth.net/confluence/x/coFAAg
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net



-- 

Jason Rotunno
System & Security Administrator
Swarthmore College
500 College Ave
Swarthmore, PA 19081
610.328.8505

Think BEFORE You Click!! Emails from Swarthmore College ITS won't be in your
Quarantine or Spam folder. We won't threaten you either! If you
receive any phishing emails, please forward them to phishing at swarthmore.edu.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20190613/0dd64a3d/attachment.html>


More information about the users mailing list