Embedded DS not setting secure _idp_saml cookie
Cantor, Scott
cantor.2 at osu.edu
Thu Jan 23 15:25:17 EST 2020
On 1/23/20, 3:23 PM, "users on behalf of Nathan Lee" <users-bounces at shibboleth.net on behalf of leenathan24 at tamu.edu> wrote:
> Is this something I am just doing wrong in my configuration of the SP’s embedded DS? Is this even a problem or am I
> misunderstanding the use of that cookie?
I don't know what controls it in the EDS but unless you're running on port 80 it doesn't rightly matter, least of all for a cookie that contains an IdP name.
> As an aside, just before sending this email I also noticed that the “shib_idp_session” cookie from the IdP is also not
> being set as secure.
That's up to the deployer.
-- Scott
More information about the users
mailing list