<div dir="ltr">All,<div><br></div><div>Previously we have been using Shibboleth IDP with an MFA login, and the first flow set as authn/External authenticator, pointing to an Apero CAS server. We are in the process of decommissioning the Apero CAS software and moving to using Shibboleth IDP for all our SAML and CAS protocol needs. </div><div><br></div><div>I have changed the login process in conf/authn/mfa-authn-config.xml to use authn/Password, and configured it so that we can authenticate via LDAP. I can successfully log into an SP via Shibboleth, and everything appears to be working with the login itself, but I appear to be missing some cookies, or some other piece of the puzzle. When we revisit the SP after a successful authentication, We are re-prompted to authenticate. <br><br>I have looked into the cookies stored in the session, and I do not see any cookies that match what we have set in idp.properties:<br><br>idp.cookie.secure = true<br>#idp.cookie.httpOnly = true<br>idp.cookie.domain = <a href="http://uni.edu">uni.edu</a><br>idp.cookie.path = /idp.stg<br>idp.cookie.maxAge = 31536000<br><br><br>I also do not see anything for the shibcas.serverName -- which matches the URL for the service.<br><br>I am assuming I am missing something obvious, but I am unable to see what it is. Can anyone point me in the right direction?</div><div><br></div><div>Thanks! <br clear="all"><div><br></div><span class="gmail_signature_prefix">-- </span><br><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><pre cols="72">Jeff Chapin,</pre>Panther eSports Adviser            <br>Systems/Applications Administrator<br>ITS-IS, University of Northern Iowa<br>Phone: 319-273-3162 Email: <a href="mailto:Jeff.Chapin@uni.edu" target="_blank">Jeff.Chapin@uni.edu</a> </div></div></div></div></div></div>