403 Forbidden Issue

Chris Lopez pez at gwu.edu
Tue Feb 1 14:54:49 UTC 2022


So at this point, I know:

my shibboleth sp configs look good and the sessions are being generated (no
errors).

my apache configs look good, there are. no file level permission issues
that could cause a 403 forbidden (no errors other than the 403 noted in the
access log)

What in the world is going on ? Someone please help before I lose my mind !

Thanks
Pez

On Tue, Jan 25, 2022 at 3:42 PM Chris Lopez <pez at gwu.edu> wrote:

> I was previously setup in a environment with coldfusion 11, apache 2.2 and
> Shibboleth SP 2.0, and we had the environment working perfectly.
>
> We have recently setup a new environment with coldfusion 2018, apache 2.4
> and Shibboleth SP 3.0. We have all of our configurations (both shibboleth,
> and apache) in place as they should be. When attempting to test, the user
> gets routed to authenticate (as it should), and the authentication process
> is successful (as it should). After authentication, it routes to /secure
> where it then shows a 403 Forbidden message.
>
> I noticed that it adds a slash at the end (/secure/), and thought that
> might be a problem, however, I don't believe that is the issue as (#1) the
> old environment behaves the same way and (#2) I added trailing slashes in
> the Location /secure/ settings as well. This had no effect, leading me to
> believe that isn't the issue.
>
> I have verified by going to /Shibboleth.sso/Sessions, checking transaction
> and shib logs, as well as using Chrome Developer Tools > Network > cookies,
> that a session indeed has been created, however the /secure Location is
> still throwing a 403 Forbidden.
>
> Our Identity guy and myself are banging our heads against the wall on this
> one... Please Help !!
>
> Thanks
> Pez
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20220201/ff482f7e/attachment.htm>


More information about the users mailing list