Issue / Bug with Unsolicited SSO after Update from IdP 3.3.1 to 3.4.3
Cantor, Scott
cantor.2 at osu.edu
Wed Mar 13 09:30:54 EDT 2019
On 3/13/19, 2:58 AM, "users on behalf of Martin Lunze" <users-bounces at shibboleth.net on behalf of martin.lunze at tu-dresden.de> wrote:
> Seems for me that the idp fails with the new version (3.4.3) if curl did not handle cookies.
> With the old version (3.3.1) it was not necessary to use the "--cookie-jar" option of curl.
That is a deployment choice, but if you didn't customize web.xml, the default copy blocks JSESSIONID from showing up on the URL.
Regardless, the IdP does not support use without cookie support in the client unless you're using the ECP flow.
-- Scott
More information about the users
mailing list