Issue / Bug with Unsolicited SSO after Update from IdP 3.3.1 to 3.4.3

Cantor, Scott cantor.2 at osu.edu
Wed Mar 13 09:30:54 EDT 2019


On 3/13/19, 2:58 AM, "users on behalf of Martin Lunze" <users-bounces at shibboleth.net on behalf of martin.lunze at tu-dresden.de> wrote:

> Seems for me that the idp fails with the new version (3.4.3) if curl did not handle cookies.
> With the old version (3.3.1) it was not necessary to use the "--cookie-jar" option of curl.

That is a deployment choice, but if you didn't customize web.xml, the default copy blocks JSESSIONID from showing up on the URL.

Regardless, the IdP does not support use without cookie support in the client unless you're using the ECP flow.

-- Scott




More information about the users mailing list