<div dir="ltr">We have an SP setup at <a href="https://createunl.com">https://createunl.com</a> (a WordPress installation). We modified .htaccess to allow /Shibboleth.sso requests to get passed to the shibd process. The application is properly directing users to the IdP but when they're sent back the browser starts looping through additional <a href="https://shib.unl.edu/idp/profile/SAML2/Redirect/SSO?SAMLRequest">https://shib.unl.edu/idp/profile/SAML2/Redirect/SSO?SAMLRequest</a> pages.<div><br></div><div>The transaction log shows successful authentication and /Shibboleth.sso/Session shows a proper session exists so I'm assuming for some reason the app isn't getting a cookie stored correctly. <div><br></div><div>When I looked over the information in the wiki related to redirect loops it mentioned making sure SSL was enabled across the app and forced when using cookieprops=https and that has already been done. Would this have something to do with the certificate being used by shibd? It's currently just a self-signed hostname certificate, does it need to match the endpoint? Or am I on the wrong trail?</div><div><br clear="all"><div><div class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><big><big>Tim Owens</big></big><br>


Co-Founder • <a href="mailto:tim@reclaimhosting.com" target="_blank">tim@reclaimhosting.com</a><br>

<img src="https://docs.google.com/uc?export=download&id=0B7kAZWcfr4JvZVhnajE5YjRHTDA&revid=0B7kAZWcfr4JvbEJOTm8wQktjdEExUzhwWEZkNHlXLzQrR0VZPQ"><br></div></div></div></div></div>
</div></div></div>