<div dir="ltr"><div dir="ltr">On Mon, Feb 13, 2023 at 1:21 PM Cantor, Scott <<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>> wrote:<br></div><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">> The day before we received this ticket we enabled the SameSite filter to address<br>
> this very issue.<br>
<br>
There are only a small set of scenarios, generally involving frames, where this is relevant. SSO mostly works fine without SameSite unless you're proxying, with a few edge cases that do not cause an error, just more frequent re-authentication.<br></blockquote><div><br></div><div> When you refer to proxying, are you talking about any type of proxy, or an IdP proxy specifically? We do have Shibboleth behind an Apache instance that's running mod_proxy_ajp.</div></div><div><br></div>-- <br><div dir="ltr" class="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><pre cols="72">Jason Rotunno
System & Security Administrator
Swarthmore College
500 College Ave
Swarthmore, PA 19081
610.328.8505<br></pre><pre cols="72"><b>VERIFY before you click!!</b>
  - Attackers make their emails look like they come from someone they don't.
  - Attackers make links look like they go to websites they don't.
  - Attackers disguise malware as receipts, invoices, faxes, etc.</pre><pre cols="72">Forward suspicious emails to <a href="mailto:phishing@swarthmore.edu" style="font-family:Arial,Helvetica,sans-serif" target="_blank">phishing@swarthmore.edu</a><span style="font-family:Arial,Helvetica,sans-serif">.</span></pre></div></div></div></div></div></div></div></div></div></div></div></div></div>