<div dir="ltr">Well I'm glad to hear it's not certificate-related. To be honest not sure why I assumed it could be other than that perhaps our SP wasn't able to decode the response from the IdP, but even as I type that I realize since the shib session gets set it is getting a proper response so that wouldn't even make sense.<div><br></div><div>I've monitored headers at every aspect of the loop and see it sending the cookie and all the URLs match up so it doesn't appear to be an issue of URL mismatch. Are there other scenarios that would cause this? Local logins work fine so I know the app is capable of setting cookies for logged in users and we've used the Shibboleth plugin successfully in the past and not run into this previously so it's a bit of a headscratcher for me.</div></div><div class="gmail_extra"><br clear="all"><div><div class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><big><big>Tim Owens</big></big><br>
Co-Founder • <a href="mailto:tim@reclaimhosting.com" target="_blank">tim@reclaimhosting.com</a><br>
<img src="https://docs.google.com/uc?export=download&id=0B7kAZWcfr4JvZVhnajE5YjRHTDA&revid=0B7kAZWcfr4JvbEJOTm8wQktjdEExUzhwWEZkNHlXLzQrR0VZPQ"><br></div></div></div></div></div>
<br><div class="gmail_quote">On Tue, Aug 23, 2016 at 10:28 AM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">On 8/23/16 10:15 AM, Tim Owens wrote:<br>
><br>
> When I looked over the information in the wiki related to redirect loops<br>
> it mentioned making sure SSL was enabled across the app and forced when<br>
> using cookieprops=https and that has already been done.<br>
<br>
</span>It remains the case that your cookies are at fault. That is always the<br>
cause of a loop. Session issued, cookie set, cookie not returned, loop.<br>
<span class=""><br>
> Would this have<br>
> something to do with the certificate being used by shibd?<br>
<br>
</span>Nope. I would be fascinated to understand why people always assume that.<br>
We probably should edit the page and just say in red "this is not a<br>
certificate issue".<br>
<span class="HOEnZb"><font color="#888888"><br>
-- Scott<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br>
</font></span></blockquote></div><br></div>