<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
</head>
<body>
<p>Hello,<br>
<br>
Maybe SElinux ? I have lost many hours cause of SElinux.<br>
<br>
Regards, Gilian.<br>
</p>
<div class="moz-cite-prefix">Le 01/02/2022 à 15:54, Chris Lopez via
users a écrit :<br>
</div>
<blockquote type="cite"
cite="mid:CAHftzFB2sAxbL_NJ2Ho6z+OaWpGyUAqx0+BuBhnaOinwOvpa7A@mail.gmail.com">
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
<div dir="ltr">So at this point, I know:
<div><br>
</div>
<div>my shibboleth sp configs look good and the sessions are
being generated (no errors).
<div><br>
</div>
<div>my apache configs look good, there are. no file level
permission issues that could cause a 403 forbidden (no
errors other than the 403 noted in the access log)
<div><br>
</div>
<div>
<div>What in the world is going on ? Someone please help
before I lose my mind !</div>
</div>
</div>
</div>
<div><br>
</div>
<div>Thanks</div>
<div>Pez</div>
</div>
<br>
<div class="gmail_quote">
<div dir="ltr" class="gmail_attr">On Tue, Jan 25, 2022 at 3:42
PM Chris Lopez <<a href="mailto:pez@gwu.edu"
moz-do-not-send="true" class="moz-txt-link-freetext">pez@gwu.edu</a>>
wrote:<br>
</div>
<blockquote class="gmail_quote" style="margin:0px 0px 0px
0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
<div dir="ltr">I was previously setup in a environment with
coldfusion 11, apache 2.2 and Shibboleth SP 2.0, and we had
the environment working perfectly.
<div><br>
</div>
<div>We have recently setup a new environment with
coldfusion 2018, apache 2.4 and Shibboleth SP 3.0. We have
all of our configurations (both shibboleth, and apache) in
place as they should be. When attempting to test, the user
gets routed to authenticate (as it should), and the
authentication process is successful (as it should). After
authentication, it routes to /secure where it then shows a
403 Forbidden message. </div>
<div><br>
</div>
<div>I noticed that it adds a slash at the end (/secure/),
and thought that might be a problem, however, I don't
believe that is the issue as (#1) the old environment
behaves the same way and (#2) I added trailing slashes in
the Location /secure/ settings as well. This had no
effect, leading me to believe that isn't the issue. </div>
<div><br>
</div>
<div>I have verified by going to /Shibboleth.sso/Sessions,
checking transaction and shib logs, as well as using
Chrome Developer Tools > Network > cookies, that a
session indeed has been created, however the /secure
Location is still throwing a 403 Forbidden.</div>
<div><br>
</div>
<div>Our Identity guy and myself are banging our heads
against the wall on this one... Please Help !!</div>
<div><br>
</div>
<div>Thanks</div>
<div>Pez</div>
</div>
</blockquote>
</div>
<br>
<fieldset class="moz-mime-attachment-header"></fieldset>
</blockquote>
</body>
</html>