Having problems with SAML auth on IdP version 4.1.3

Cantor, Scott cantor.2 at osu.edu
Tue Jul 27 15:08:18 UTC 2021


On 7/27/21, 10:56 AM, "users on behalf of Duncan Sinclair" <users-bounces at shibboleth.net on behalf of d.sinclair at abertay.ac.uk> wrote:

>    I've got a HAR file of the web traffic if you're interested, but having had a look at it myself, I'm beginning to
> think it's a 'SameSite' problem.

That would be on the way back in (you weren't specific about when this was happening), and I identified that in the original bug report you were looking at. That is 100% SameSite, I know that for certain.

>    On the POST back to the Shibboleth Authn end-point, the shib_idp_* and JSESSION cookies are being blocked
> due to SameSite restrictions.

Yes, they would be, provided it happens after the two minute window (yet another wonderful gift from Google).

>    Anybody got any tips on how to get the correct 'SafeSite' values set?

We documented that under SameSite in the wiki, and I also updated that page with the fact that proxying is broken without the workaround.

-- Scott




More information about the users mailing list