idp.storage.clientSessionStorageName cookie name

Tom Andrew tom.andrew at york.ac.uk
Fri Jul 26 10:46:30 UTC 2024


Hi,

The v5.0.0 release notes, in the section about changes to cookie
names/paths it says "The workaround at present is to change the cookie
name used for the storage data using the
idp.storage.clientSessionStorageName property. (In new installs, this
has already been done.)". However in the property reference for the
storage configuration
(https://shibboleth.atlassian.net/wiki/spaces/IDP5/pages/3199509576/StorageConfiguration)
the default value for that property still appears to be
"shib_idp_session_ss". Have I misunderstood the mechanism by which
this change would have happened for new installs (i.e. not by the
property default)? And if that is the case is the name of this cookie
in new installs documented anywhere?

As an aside, while I believe our situation is the one described in
that passage of the release notes, I don't think I am currently seeing
the issue described (after the upgrade login is required once, but
then SSO works as usual) - however I'm assuming this may be down to
individual browser behaviours of how they deal with multiple cookies
of the same name but different paths.

--
Tom Andrew
Infrastructure Engineer (Linux)
University of York


More information about the users mailing list