SSO Session Cookies

Jeff Chapin jeff.chapin at uni.edu
Wed Feb 21 14:47:02 UTC 2024


All,

Previously we have been using Shibboleth IDP with an MFA login, and the
first flow set as authn/External authenticator, pointing to an Apero CAS
server. We are in the process of decommissioning the Apero CAS software and
moving to using Shibboleth IDP for all our SAML and CAS protocol needs.

I have changed the login process in conf/authn/mfa-authn-config.xml to use
authn/Password, and configured it so that we can authenticate via LDAP. I
can successfully log into an SP via Shibboleth, and everything appears to
be working with the login itself, but I appear to be missing some
cookies, or some other piece of the puzzle. When we revisit the SP after a
successful authentication, We are re-prompted to authenticate.

I have looked into the cookies stored in the session, and I do not see any
cookies that match what we have set in idp.properties:

idp.cookie.secure = true
#idp.cookie.httpOnly = true
idp.cookie.domain = uni.edu
idp.cookie.path = /idp.stg
idp.cookie.maxAge = 31536000


I also do not see anything for the shibcas.serverName -- which matches the
URL for the service.

I am assuming I am missing something obvious, but I am unable to see what
it is. Can anyone point me in the right direction?

Thanks!

-- 

Jeff Chapin,

Panther eSports Adviser
Systems/Applications Administrator
ITS-IS, University of Northern Iowa
Phone: 319-273-3162 Email: Jeff.Chapin at uni.edu
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20240221/c1ce7249/attachment.htm>


More information about the users mailing list