<div dir="ltr"><div dir="ltr">On Wed, Jun 12, 2019 at 5:30 PM Cantor, Scott <<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>> wrote:<br></div><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">> But after restarting Shib the Secure flag is still being used. Is this a bug (I<br>
> searched for a bug related to this but didn't find anything), or am I just missing<br>
> something?<br>
<br>
Any cookies the IdP sets are governed by it, others are not and would be controlled in whatever way governs them.<br>
<br>
-- ScottĀ <br></blockquote></div><br clear="all"><div>These would be cookies set by the IdP; for example (this is after changing idp.cookie.secure to false):</div><div><br></div><blockquote style="margin:0 0 0 40px;border:none;padding:0px"><div>HTTP/1.1 302</div><div>Set-Cookie: JSESSIONID=8D9E91ADF81898B4299A59E6703DE060; Path=/idp; Secure; HttpOnly</div><div>Cache-Control: no-store</div><div>X-Frame-Options: DENY</div><div>Strict-Transport-Security: max-age=0</div><div>Content-Security-Policy: frame-ancestors 'none';</div><div>Location: /idp/profile/cas/login?execution=e1s1</div><div>Content-Length: 0</div><div>Date: Wed, 12 Jun 2019 19:20:14 GMT</div><div>Connection: close</div></blockquote><div><br></div><div>I ended up finding a thread where someone else was having the same problem and you mentioned that web.xml has its own settings (<a href="http://shibboleth.1660669.n2.nabble.com/NoSuchFlowExecutionException-e1s1-td7642152.html">http://shibboleth.1660669.n2.nabble.com/NoSuchFlowExecutionException-e1s1-td7642152.html</a>). Does that mean that the latter overrides the former?</div><div><br></div>-- <br><div dir="ltr" class="m_6653927261421790562gmail_signature"><div dir="ltr"><div><div dir="ltr"><div dir="ltr"><pre cols="72">Jason Rotunno
System & Security Administrator
Swarthmore College
500 College Ave
Swarthmore, PA 19081
610.328.8505<br></pre><pre cols="72">Think BEFORE You Click!! Emails from Swarthmore College ITS won't be in your
Quarantine or Spam folder. We won't threaten you either! If you
receive any phishing emails, please forward them to <a href="mailto:phishing@swarthmore.edu" target="_blank">phishing@swarthmore.edu</a>.<br></pre></div></div></div></div></div></div>