Attempt to spoof header (HTTP_SHIBSESSIONID:) was detected.

Cantor, Scott cantor.2 at osu.edu
Mon Jul 21 16:28:38 UTC 2025


> So removing this setting should then remove the error being
> reported? We will test this tonight.

Spoof detection is entirely bypassed when headers ore off, it serves no purpose.

> What would be the best approach to tracking down the
> header causing the issue? Presumably this occurs after
> authentication with the IDP has taken place.

It's got nothing to do with the IdP, you have an HTTP request into that server carrying a header or headers that the SP is guarding, full stop. Why is not for me to say.

-- Scott




More information about the users mailing list