Post upgrade to 4.2.1 - Invalid cookie header
Cantor, Scott
cantor.2 at osu.edu
Fri Jul 8 18:51:52 UTC 2022
On 7/7/22, 9:03 PM, "users on behalf of Jay Fowler" <users-bounces at shibboleth.net on behalf of fowler at csufresno.edu> wrote:
> Just a guess ... Perhaps the ordering of the date fields is preventing the client from translating it correctly?
My code has always used DD Mon YYYY, that's the intended syntax, though max-age is actually the normal way now.
> The http metadata was updated successfully so it didn't limit anything. However the error still showed in the
> logs and only seems to be apply to a few providers, namely:
If they're not signing and properly expiring that metadata, it's not usable anyway. Remote metadata from third party federations is the only proper way to consume remote metadata. Vendors don't do this correctly and should never be trusted like that, and that's even *if* you apply the proper filters to prevent one from asserting metadata for another, which you are probably not doing.
-- Scott
More information about the users
mailing list