Looping issue where no cookies are being sent in the response (Azure ad, shibboleth sp)
Robert Bradley
robert.bradley at it.ox.ac.uk
Fri Jul 29 15:36:46 UTC 2022
On 29/07/2022 15:15, Cantor, Scott via users wrote:
> On 7/29/22, 10:09 AM, "users on behalf of Peter Schober via users" <users-bounces at shibboleth.net on behalf of users at shibboleth.net> wrote:
>
>> This OTOH makes no sense -- though the software probably protects you
>> from shooting yourself in the foot that way by ignoring it, AFAIR:
>
> It tries, but the fact that it's not means the virtualization *is* there and is preventing the SP from recognizing the request as a handler submission.
>
> The SP likely sees it as http and with handlerSSL="true" that will be ignored and passed along, then protected by the requireSession rule and loops.
>
I wouldn't rule out issues with not setting SameSite=None on cookies
either, based on past experience.
--
Dr Robert Bradley
Identity and Access Management Team, IT Services, University of Oxford
-------------- next part --------------
A non-text attachment was scrubbed...
Name: OpenPGP_signature
Type: application/pgp-signature
Size: 840 bytes
Desc: OpenPGP digital signature
URL: <http://shibboleth.net/pipermail/users/attachments/20220729/5616b505/attachment.sig>
More information about the users
mailing list