Shibboleth SP & Okta IdP Redirect Looping
Cantor, Scott
cantor.2 at osu.edu
Wed Aug 5 20:38:51 UTC 2020
Just in terms of tracing, the correct sequence of traced URLs would have to be:
GET protected path at SP
- IdP traffic
POST to /Shibboleth.sso/SAML2/POST
GET to original protected path
And if that were happening, loop or not, the transaction.log would be clearly showing a session created. And /Shibboleth.sso/Session should dump out that session.
-- Scott
More information about the users
mailing list