<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
</head>
<body>
<div dir="ltr" text-align="left">
<div>
<meta name="Generator" content="Microsoft Exchange Server">
<!-- converted from text --><style><!-- .EmailQuote { margin-left: 1pt; padding-left: 4pt; border-left: #800000 2px solid; } --></style></div>
<font size="2"><span style="font-size:11pt;">
<div class="PlainText" dir="ltr" style="text-align: left;"><span style="font-size: 11pt;">Dear Peter,</span><br>
</div>
<div class="PlainText"><br>
In our believe we need the rewrite rule because, we want all traffic to go over a secure SSL connection.<br>
<br>
As I was trying to describe in my initial mail, we have the SP and the Webapp running on two different machines. Even more, we run them in different domains.<br>
So we must switch from one SSL connection to another. Correct me if I am wrong on that.<br>
What we keeping asking ourselves is, how is the SP supposed to know where to send me after a successful login?<br>
<br>
        We did as suggested by Scott, we took the         ShibUseHeaders On and the ApplicationOverride out from our configuration, but that broad us only into a loop.<br>
<br>
Greetings</div>
<div class="PlainText" dir="ltr" style="text-align: left;"> and thanks again. </div>
<div class="PlainText" dir="ltr" style="text-align: left;"><br>
</div>
<div class="PlainText">Thomas stopinski<br>
-----Ursprüngliche Nachricht-----<br>
Von: users <users-bounces@shibboleth.net> Im Auftrag von Peter Schober<br>
Gesendet: Donnerstag, 7. November 2019 16:55<br>
An: users@shibboleth.net<br>
Betreff: Re: Cookie spoof<br>
<br>
* Stopinski, Thomas Thaddäus <thstopinski@ukaachen.de> [2019-11-07 16:33]:<br>
> We have an Apache webserver and a SP running on a VM on Ubuntu 18.04 <br>
> At the beginning we want to protect a asp .net core Webapp, that runs <br>
> on Azure Cloud service. Everything is up-to-date.<br>
<br>
It would be easier if you explained why you require the rewrite rule and especially why you're proxying requests to yourself?<br>
(You have a ProxyPass to <a href="https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth-ourserver.com&amp;data=02%7C01%7C%7C880bf24a0efe4dd6f44808d7639af53f%7C5a6d5ee56edf4a26ba93f5872dbb9614%7C0%7C1%7C637087389496337159&amp;sdata=nuhy577jRnf%2BwwHxeyBOV%2FZVhJuUkOMOY6On%2B9QgaMQ%3D&amp;reserved=0">
https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth-ourserver.com&amp;data=02%7C01%7C%7C880bf24a0efe4dd6f44808d7639af53f%7C5a6d5ee56edf4a26ba93f5872dbb9614%7C0%7C1%7C637087389496337159&amp;sdata=nuhy577jRnf%2BwwHxeyBOV%2FZVhJuUkOMOY6On%2B9QgaMQ%3D&amp;reserved=0</a>
 within the TLS-vhost for shibboleth-ourserver.com)<br>
<br>
-peter<br>
--<br>
For Consortium Member technical support, see <a href="https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwiki.shibboleth.net%2Fconfluence%2Fx%2FcoFAAg&amp;data=02%7C01%7C%7C880bf24a0efe4dd6f44808d7639af53f%7C5a6d5ee56edf4a26ba93f5872dbb9614%7C0%7C1%7C637087389496337159&amp;sdata=P6SGOnWOpX2PyEidXYZAsWzAbaVxq5Bwc1VtU8NR61M%3D&amp;reserved=0">
https://eur02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwiki.shibboleth.net%2Fconfluence%2Fx%2FcoFAAg&amp;data=02%7C01%7C%7C880bf24a0efe4dd6f44808d7639af53f%7C5a6d5ee56edf4a26ba93f5872dbb9614%7C0%7C1%7C637087389496337159&amp;sdata=P6SGOnWOpX2PyEidXYZAsWzAbaVxq5Bwc1VtU8NR61M%3D&amp;reserved=0</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font></div>
</body>
</html>