<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Niva,</div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
What change has Jaegger made?</div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
We received an email from them saying they were changing *their* cookies to SameSite=None. That won't help with SSO, though. We want them to change from HTTP-Post to HTTP-Redirect binding for their SAML requests. We (Oregon State University) have asked them
to make that change, but they have not agreed to it yet.</div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Thanks,<br>
</div>
<div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div id="Signature">
<div></div>
<div></div>
<div style="font-family:"Courier New",monospace; font-size:12pt; color:rgb(0,0,0)">
<span style="font-family:Arial,Helvetica,sans-serif">Andy Morgan</span><span><br>
</span></div>
<div style="font-family:"Courier New",monospace; font-size:12pt; color:rgb(0,0,0)">
<div><span style="font-family:Arial,Helvetica,sans-serif">Identity & Access Management</span><br>
</div>
<div><span style="font-family:Arial,Helvetica,sans-serif">Oregon State University</span><br>
</div>
</div>
</div>
</div>
<div>
<div id="appendonsend"></div>
<div style="font-family:Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<hr tabindex="-1" style="display:inline-block; width:98%">
<div id="divRplyFwdMsg" dir="ltr"><font style="font-size:11pt" face="Calibri, sans-serif" color="#000000"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Niva Agmon <niva.agmon@temple.edu><br>
<b>Sent:</b> Thursday, January 30, 2020 10:05 AM<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Subject:</b> RE: Looking for other third-party SPs that fail with stricter SameSite settings</font>
<div> </div>
</div>
<div class="BodyFragment"><font size="2"><span style="font-size:11pt">
<div class="PlainText">We were notified about Jagger (SciQuest) today. <br>
Just tried it and it looks like at least the SSO part is working, but will continue testing. They recommended checking with their test site and the SameSite settings enabled in Chrome 79.<br>
<br>
Niva Agmon<br>
Temple University<br>
<br>
-----Original Message-----<br>
From: users <users-bounces@shibboleth.net> On Behalf Of shibboleth655@lewenberg.com<br>
Sent: Friday, January 24, 2020 2:22 PM<br>
To: Shib Users <users@shibboleth.net><br>
Subject: Looking for other third-party SPs that fail with stricter SameSite settings<br>
<br>
External Email<br>
<br>
We are testing our Shibboleth IdP against the important SPs using the<br>
stricter SameSite settings that will be used in the upcoming Chrome 80<br>
release (see <a href="https://www.chromium.org/updates/same-site">https://www.chromium.org/updates/same-site</a>).<br>
<br>
We have found that the following SPs _fail_, that is, we cannot login at<br>
all:<br>
<br>
- ServiceNow<br>
- Instructure<br>
- Rimeto<br>
<br>
If you have found other third-party SPs that don't work with these new<br>
settings please reply to this post and let us know.<br>
<br>
Thanks, Adam Lewenberg<br>
Stanford University<br>
<br>
<br>
--<br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg">
https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg">
https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font></div>
</div>
</body>
</html>