<div dir="ltr"><div>This is what we're doing at Auth0 (in production) as of a couple months ago--as far as I know it's worked really well (except for someone using Mulesoft, which tried to send them back as multiple "Cookie" headers in the request--not allowed per HTTP 1.1 and nginx was having none of it). The downside is the browser still throws the SameSite errors, so I have to remind folks it's normal to see that error for the backwards compatible version of the cookie. <br></div><div><br>-- <br><div dir="ltr" class="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div>Matt MacAdam</div><div>Senior Developer Support Engineer</div><div>Auth0 (Bellevue, USA, Pacific Time)</div></div></div></div></div></div><div><br></div><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Thu, Jan 30, 2020 at 2:08 PM Niva Agmon <<a href="mailto:niva.agmon@temple.edu">niva.agmon@temple.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
<div lang="EN-US">
<div class="gmail-m_1356285172064320900WordSection1">
<p class="gmail-m_1356285172064320900MsoPlainText">Andy,<u></u><u></u></p>
<p class="gmail-m_1356285172064320900MsoPlainText"><u></u> <u></u></p>
<p class="gmail-m_1356285172064320900MsoPlainText">> What change has Jaegger made?<u></u><u></u></p>
<p class="gmail-m_1356285172064320900MsoPlainText"><u></u> <u></u></p>
<p class="gmail-m_1356285172064320900MsoPlainText">They’re setting both new and "legacy" cookies in their test environment. (Definitely didn't change to HTTP-Redirect binding as far as I can see…)<u></u><u></u></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:"Calibri",sans-serif;color:rgb(31,73,125)"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:"Calibri",sans-serif;color:rgb(31,73,125)">Set-Cookie: sqsession=6a44....; Path=/apps/Router; Secure; HttpOnly; SameSite=None;<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:"Calibri",sans-serif;color:rgb(31,73,125)">Set-Cookie: sqsession_legacy=6a443...; Path=/apps/Router; Secure; HttpOnly<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:"Calibri",sans-serif;color:rgb(31,73,125)">Set-Cookie: squserid=399...; Path=/apps/Router; Secure; HttpOnly; SameSite=None;<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:"Calibri",sans-serif;color:rgb(31,73,125)">Set-Cookie: squserid_legacy=399..; Path=/apps/Router; Secure; HttpOnly<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:"Calibri",sans-serif;color:rgb(31,73,125)"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:"Calibri",sans-serif;color:rgb(31,73,125)">Niva<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11pt;font-family:"Calibri",sans-serif;color:rgb(31,73,125)"><u></u> <u></u></span></p>
<div>
<div style="border-color:rgb(225,225,225) currentcolor currentcolor;border-style:solid none none;border-width:1pt medium medium;padding:3pt 0in 0in">
<p class="MsoNormal"><b><span style="font-size:11pt;font-family:"Calibri",sans-serif">From:</span></b><span style="font-size:11pt;font-family:"Calibri",sans-serif"> users <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a>>
<b>On Behalf Of </b>Morgan, Andrew Jason<br>
<b>Sent:</b> Thursday, January 30, 2020 1:11 PM<br>
<b>To:</b> Shib Users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br>
<b>Subject:</b> Re: Looking for other third-party SPs that fail with stricter SameSite settings<u></u><u></u></span></p>
</div>
</div>
<p class="MsoNormal"><u></u> <u></u></p>
<div style="border:1.5pt solid black;padding:4pt;margin:11.25pt">
<p class="MsoNormal" style="text-align:center;background:rgb(255,255,128) none repeat scroll 0% 0%" align="center">
<b><span style="font-size:8.5pt;font-family:"Open Sans",serif;color:black">External Email<u></u><u></u></span></b></p>
</div>
<div>
<div>
<p class="MsoNormal"><span style="font-family:"Arial",sans-serif;color:black">Niva,<u></u><u></u></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Arial",sans-serif;color:black"><u></u> <u></u></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Arial",sans-serif;color:black">What change has Jaegger made?<u></u><u></u></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Arial",sans-serif;color:black"><u></u> <u></u></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Arial",sans-serif;color:black">We received an email from them saying they were changing *their* cookies to SameSite=None. That won't help with SSO, though. We want them to change from HTTP-Post to HTTP-Redirect
binding for their SAML requests. We (Oregon State University) have asked them to make that change, but they have not agreed to it yet.<u></u><u></u></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Arial",sans-serif;color:black"><u></u> <u></u></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Arial",sans-serif;color:black">Thanks,<u></u><u></u></span></p>
</div>
<div>
<div>
<p class="MsoNormal"><span style="font-family:"Arial",sans-serif;color:black"><u></u> <u></u></span></p>
</div>
<div id="gmail-m_1356285172064320900Signature">
<div>
<p class="MsoNormal"><span style="font-family:"Arial",sans-serif;color:black">Andy Morgan</span><span style="font-family:"Courier New";color:black"><u></u><u></u></span></p>
</div>
<div>
<div>
<p class="MsoNormal"><span style="font-family:"Arial",sans-serif;color:black">Identity & Access Management</span><span style="font-family:"Courier New";color:black"><u></u><u></u></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Arial",sans-serif;color:black">Oregon State University</span><span style="font-family:"Courier New";color:black"><u></u><u></u></span></p>
</div>
</div>
</div>
</div>
<div>
<div>
<p class="MsoNormal"><span style="font-family:"Arial",sans-serif;color:black"><u></u> <u></u></span></p>
</div>
<div class="MsoNormal" style="text-align:center" align="center">
<hr width="98%" size="2" align="center">
</div>
<div id="gmail-m_1356285172064320900divRplyFwdMsg">
<p class="MsoNormal"><b><span style="font-size:11pt;font-family:"Calibri",sans-serif;color:black">From:</span></b><span style="font-size:11pt;font-family:"Calibri",sans-serif;color:black"> users <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a>>
on behalf of Niva Agmon <<a href="mailto:niva.agmon@temple.edu" target="_blank">niva.agmon@temple.edu</a>><br>
<b>Sent:</b> Thursday, January 30, 2020 10:05 AM<br>
<b>To:</b> Shib Users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br>
<b>Subject:</b> RE: Looking for other third-party SPs that fail with stricter SameSite settings</span>
<u></u><u></u></p>
<div>
<p class="MsoNormal"> <u></u><u></u></p>
</div>
</div>
<div>
<div>
<p class="MsoNormal"><span style="font-size:11pt">We were notified about Jagger (SciQuest) today.
<br>
Just tried it and it looks like at least the SSO part is working, but will continue testing. They recommended checking with their test site and the SameSite settings enabled in Chrome 79.<br>
<br>
Niva Agmon<br>
Temple University<br>
<br>
-----Original Message-----<br>
From: users <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a>> On Behalf Of
<a href="mailto:shibboleth655@lewenberg.com" target="_blank">shibboleth655@lewenberg.com</a><br>
Sent: Friday, January 24, 2020 2:22 PM<br>
To: Shib Users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br>
Subject: Looking for other third-party SPs that fail with stricter SameSite settings<br>
<br>
External Email<br>
<br>
We are testing our Shibboleth IdP against the important SPs using the<br>
stricter SameSite settings that will be used in the upcoming Chrome 80<br>
release (see <a href="https://www.chromium.org/updates/same-site" target="_blank">https://www.chromium.org/updates/same-site</a>).<br>
<br>
We have found that the following SPs _fail_, that is, we cannot login at<br>
all:<br>
<br>
- ServiceNow<br>
- Instructure<br>
- Rimeto<br>
<br>
If you have found other third-party SPs that don't work with these new<br>
settings please reply to this post and let us know.<br>
<br>
Thanks, Adam Lewenberg<br>
Stanford University<br>
<br>
<br>
--<br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" target="_blank">
https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">
users-unsubscribe@shibboleth.net</a><br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" target="_blank">
https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">
users-unsubscribe@shibboleth.net</a><u></u><u></u></span></p>
</div>
</div>
</div>
</div>
</div>
</div>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a></blockquote></div><br clear="all"><br><div dir="ltr" class="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div><br></div></div></div></div></div></div>