<html><head><meta http-equiv="Content-Type" content="text/html charset=windows-1252"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;">Following up, the vendor has corrected their description of what they are doing to state they are issuing the SAML request in an iframe.<div>I take it the IdP log message&nbsp;</div><div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194); position: static; z-index: auto; font-size: 11px;">WARN...No login context available, unable to proceed with authentication</div></div><div><div><div>reflects that inability to use cookies in the iframe. &nbsp;</div><div><br></div><div>Thanks to Mike and Scott’s hints that the vendor was using frames, I found an interesting if ultimately inconclusive thread from 2008 which I relayed to the vendor.</div><div><div><span style="color: rgb(51, 51, 51); background-color: rgb(255, 255, 255);"><br></span></div></div></div></div><blockquote style="margin: 0 0 0 40px; border: none; padding: 0px;"><div><div><div><div><span style="color: rgb(51, 51, 51); background-color: rgb(255, 255, 255);">Chad La Joie responding to similar errors in 2008 email discussion:</span></div></div></div></div><div><div><div><div><blockquote type="cite"><span style="color: rgb(51, 51, 51); background-color: rgb(255, 255, 255);">Yeah, I'm pretty sure this is an issue with IFRAMEs not sending cookies</span></blockquote></div></div></div></div><div><div><div><div><blockquote type="cite"><span style="color: rgb(51, 51, 51); background-color: rgb(255, 255, 255);">like a normal frame would. Scott and I were talking about this the</span></blockquote></div></div></div></div><div><div><div><div><blockquote type="cite"><span style="color: rgb(51, 51, 51); background-color: rgb(255, 255, 255);">other day for other reasons. You'll need to read up on IFRAMEs and how</span></blockquote></div></div></div></div><div><div><div><div><blockquote type="cite"><span style="color: rgb(51, 51, 51); background-color: rgb(255, 255, 255);">your browser handles them.</span></blockquote></div></div></div></div><div><div><div><div><br></div></div></div></div><div><div><div><div>Scott Cantor in the same 2008 discussion:</div></div></div></div><div><div><div><div><blockquote type="cite"><span style="color: rgb(51, 51, 51); background-color: rgb(255, 255, 255);">Particularly when SSL is involved. Our experience at OSU, with fairly minimal&nbsp;</span></blockquote></div></div></div></div><div><div><div><div><blockquote type="cite"><span style="color: rgb(51, 51, 51); background-color: rgb(255, 255, 255);">testing, is that frames are unusable with cookie-based applications when SSL&nbsp;</span></blockquote></div></div></div></div><div><div><div><div><blockquote type="cite"><span style="color: rgb(51, 51, 51); background-color: rgb(255, 255, 255);">is used (unless all the frames are coming from the same server of course),&nbsp;</span></blockquote></div></div></div></div><div><div><div><div><blockquote type="cite"><span style="color: rgb(51, 51, 51); background-color: rgb(255, 255, 255);">and we haven't spent much time trying to get around it.</span></blockquote></div></div></div></div><div><div><div><div><br></div></div></div></div><div><div><div><div>Jim Fox (U Washington) opines:</div></div></div></div><div><div><div><div><blockquote type="cite"><span style="color: rgb(51, 51, 51); background-color: rgb(255, 255, 255);">A login url in an iframe, even if it did work, is inherently insecure</span></blockquote></div></div></div></div><div><div><div><div><blockquote type="cite"><span style="color: rgb(51, 51, 51); background-color: rgb(255, 255, 255);">and subject to easy attacks. The user has no convient way to</span></blockquote></div></div></div></div><div><div><div><div><blockquote type="cite"><span style="color: rgb(51, 51, 51); background-color: rgb(255, 255, 255);">identify the source of the login page. That's why the login</span></blockquote></div></div></div></div><div><div><div><div><blockquote type="cite"><span style="color: rgb(51, 51, 51); background-color: rgb(255, 255, 255);">is always on a page of its own.</span></blockquote></div></div></div></div></blockquote><div><div><div><br></div><div>In discussion today, the vendor agreed to replace use of iframe with pop-up window in their next release in about a month’s time.</div><div><br></div><div>Thanks all,</div><div><br></div><div>David Bantz</div><div>U Alaska</div><div><br></div><div>&nbsp;On Oct 14, 2014, at 18:52, Cantor, Scott &lt;<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>&gt; wrote:</div><br class="Apple-interchange-newline"><blockquote type="cite">On 10/14/14, 10:39 PM, "David Bantz" &lt;<a href="mailto:dabantz@alaska.edu">dabantz@alaska.edu</a>&gt; wrote:<br><blockquote type="cite"><br>Going from relayed user report of the time, I see the following line in<br>the IdP logs that reflect this failed attempt:<br></blockquote><br>Then they're probably not using a pop-up, but a frame.<br><br>-- Scott<br><br>-- <br>To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br></blockquote></div><br></div></body></html>