<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div class="elementToProof" style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Hi David,</div>
<div class="elementToProof" style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Maybe the problem has something to do with sameSite cookies? I remember there being some strange time limits on how Chrome (and Firefox?) handle cookies without sameSite set. I'm sure others on this list know more about it than me... The inconsistency of
the SSO session cookie behavior is what reminds me of sameSite.</div>
<div class="elementToProof" style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Andy</div>
<div class="elementToProof" style="font-family: Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div id="appendonsend"></div>
<hr style="display:inline-block;width:98%" tabindex="-1">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of IAM David Bantz via users <users@shibboleth.net><br>
<b>Sent:</b> Thursday, February 6, 2025 4:39 PM<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Cc:</b> IAM David Bantz <dabantz@alaska.edu><br>
<b>Subject:</b> SP/IdP not honoring SSO session</font>
<div> </div>
</div>
<div>
<p><span style="color:#D73F09">[This email originated from outside of OSU. Use caution with links and attachments.]</span></p>
<div>
<div dir="ltr">A newish service inconsistently honors users' existing SSO sessions.<br>
<br>
The initial signin link (in our student portal) issues a request to a service with Issuer and ACS suggesting OAuth:<br>
<br>
<span class="x_gmail-hljs-tag" style="font-family:SFMono-Regular,Menlo,Monaco,Consolas,"Lucida Console","Liberation Mono","Courier New",Courier,monospace; font-size:10.6667px"><<span class="x_gmail-hljs-name">saml2p:AuthnRequest</span>
<span class="x_gmail-hljs-attr">xmlns:saml2p</span>=<span class="x_gmail-hljs-string">"urn:oasis:names:tc:SAML:2.0:protocol"</span>
<span class="x_gmail-hljs-attr">AssertionConsumerServiceURL</span>=<span class="x_gmail-hljs-string">"https://....oauth....com:443/saml/SSO"</span>
<span class="x_gmail-hljs-attr">Destination</span>=<span class="x_gmail-hljs-string">"<a href="https://sso.civitaslearning.com/realms/alaska-prod/protocol/saml" originalsrc="https://sso.civitaslearning.com/realms/alaska-prod/protocol/saml" shash="M7Yi6YqqfG73aHvDJrHf9zMcS6PfKsuU+kn/RX3RtPZdHpA37d4zu/lINHdsiccHl+GsyXKedeZK/nlWPLbYOdmC4nOaqMKzat2oZoTdhNFajPFMh+2PMraDujsYMtO7y4orQKErREsRxKIToR+Ohdv1DerKSvDFZAVijCnoz0c=">https://sso.civitaslearning.com/realms/alaska-prod/protocol/saml</a>"</span>
<span class="x_gmail-hljs-attr">ForceAuthn</span>=<span class="x_gmail-hljs-string">"false"...</span>
<span class="x_gmail-hljs-attr">IsPassive</span>=<span class="x_gmail-hljs-string">"false"</span>
<span class="x_gmail-hljs-attr">IssueInstant</span>=<span class="x_gmail-hljs-string">"..."</span>
<span class="x_gmail-hljs-attr">ProtocolBinding</span>=<span class="x_gmail-hljs-string">"urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"</span>
<span class="x_gmail-hljs-attr">Version</span>=<span class="x_gmail-hljs-string">"2.0"</span> ></span><span style="color:rgb(56,56,61); font-family:SFMono-Regular,Menlo,Monaco,Consolas,"Lucida Console","Liberation Mono","Courier New",Courier,monospace; font-size:10.6667px">
</span><span class="x_gmail-hljs-tag" style="font-family:SFMono-Regular,Menlo,Monaco,Consolas,"Lucida Console","Liberation Mono","Courier New",Courier,monospace; font-size:10.6667px"><<span class="x_gmail-hljs-name">saml2:Issuer
</span><span class="x_gmail-hljs-attr">xmlns:saml2</span>=<span class="x_gmail-hljs-string">"urn:oasis:names:tc:SAML:2.0:assertion"</span>>
</span><span style="color:rgb(56,56,61); font-family:SFMono-Regular,Menlo,Monaco,Consolas,"Lucida Console","Liberation Mono","Courier New",Courier,monospace; font-size:10.6667px">https://....oauth....com:443/saml</span><span class="x_gmail-hljs-tag" style="font-family:SFMono-Regular,Menlo,Monaco,Consolas,"Lucida Console","Liberation Mono","Courier New",Courier,monospace; font-size:10.6667px"></<span class="x_gmail-hljs-name">saml2:Issuer</span>></span><span style="color:rgb(56,56,61); font-family:SFMono-Regular,Menlo,Monaco,Consolas,"Lucida Console","Liberation Mono","Courier New",Courier,monospace; font-size:10.6667px">
</span><span class="x_gmail-hljs-tag" style="font-family:SFMono-Regular,Menlo,Monaco,Consolas,"Lucida Console","Liberation Mono","Courier New",Courier,monospace; font-size:10.6667px"></<span class="x_gmail-hljs-name">saml2p:AuthnRequest</span>>
</span><span class="x_gmail-hljs-tag" style=""><font face="arial, sans-serif" style="">That service in turn sends a request to our institutional SSO (Shibb IdP):
</font></span><span class="x_gmail-hljs-tag" style=""><font face="SFMono-Regular, Menlo, Monaco, Consolas, Lucida Console, Liberation Mono, Courier New, Courier, monospace" style="font-size:10.6667px"></font><span class="x_gmail-hljs-tag" style="font-size:10.6667px; font-family:SFMono-Regular,Menlo,Monaco,Consolas,"Lucida Console","Liberation Mono","Courier New",Courier,monospace"><<span class="x_gmail-hljs-name">samlp:AuthnRequest</span>
<span class="x_gmail-hljs-attr">xmlns:samlp</span>=<span class="x_gmail-hljs-string">"urn:oasis:names:tc:SAML:2.0:protocol"</span>
<span class="x_gmail-hljs-attr">xmlns</span>=<span class="x_gmail-hljs-string">"urn:oasis:names:tc:SAML:2.0:assertion"</span>
<span class="x_gmail-hljs-attr">xmlns:saml</span>=<span class="x_gmail-hljs-string">"urn:oasis:names:tc:SAML:2.0:assertion"</span>
<span class="x_gmail-hljs-attr">AssertionConsumerServiceURL</span>=<span class="x_gmail-hljs-string">"<a href="https://sso.">https://sso.</a>.../endpoint"</span>
<span class="x_gmail-hljs-attr">Destination</span>=<span class="x_gmail-hljs-string">"<a href="https://idp.alaska.edu/idp/profile/SAML2/POST/SSO" originalsrc="https://idp.alaska.edu/idp/profile/SAML2/POST/SSO" shash="lJQHqBIn2PqMnSS3Rpk35ZHQnMghAh7m2icDAgFvXxxP5fqbwKV9VB2yefJkv56qdiYtHi3HEDtdbddTlFJj2QkXNUmFqGsQBdNdC6vjCwp14ihjmbDgRh0eyMQ0kYDOt04sbkkOK6LtNvmnSxP53UWva7LVxGm6VdE2J0mzX/8=">https://idp.alaska.edu/idp/profile/SAML2/POST/SSO</a>"</span>
<span class="x_gmail-hljs-attr">ForceAuthn</span>=<span class="x_gmail-hljs-string">"false"</span>
<span class="x_gmail-hljs-attr">IssueInstant</span>=<span class="x_gmail-hljs-string">"..."</span>
<span class="x_gmail-hljs-attr">ProtocolBinding</span>=<span class="x_gmail-hljs-string">"urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"</span>
<span class="x_gmail-hljs-attr">Version</span>=<span class="x_gmail-hljs-string">"2.0"</span> ></span><span style="font-size:10.6667px; font-family:SFMono-Regular,Menlo,Monaco,Consolas,"Lucida Console","Liberation Mono","Courier New",Courier,monospace; color:rgb(56,56,61)">
</span><span class="x_gmail-hljs-tag" style="font-size:10.6667px; font-family:SFMono-Regular,Menlo,Monaco,Consolas,"Lucida Console","Liberation Mono","Courier New",Courier,monospace"><<span class="x_gmail-hljs-name">saml:Issuer</span>></span><span style="font-size:10.6667px; font-family:SFMono-Regular,Menlo,Monaco,Consolas,"Lucida Console","Liberation Mono","Courier New",Courier,monospace; color:rgb(56,56,61)"><a href="https://sso.">https://sso.</a>...</</span><span class="x_gmail-hljs-tag" style="font-size:10.6667px; font-family:SFMono-Regular,Menlo,Monaco,Consolas,"Lucida Console","Liberation Mono","Courier New",Courier,monospace"><span class="x_gmail-hljs-name">saml:Issuer</span>></span><span style="font-size:10.6667px; font-family:SFMono-Regular,Menlo,Monaco,Consolas,"Lucida Console","Liberation Mono","Courier New",Courier,monospace; color:rgb(56,56,61)">
</span><span class="x_gmail-hljs-tag" style=""><font face="SFMono-Regular, Menlo, Monaco, Consolas, Lucida Console, Liberation Mono, Courier New, Courier, monospace" style="font-size:10.6667px"></</font><span class="x_gmail-hljs-name" style="font-size:10.6667px; font-family:SFMono-Regular,Menlo,Monaco,Consolas,"Lucida Console","Liberation Mono","Courier New",Courier,monospace">samlp:AuthnRequest</span><font face="SFMono-Regular, Menlo, Monaco, Consolas, Lucida Console, Liberation Mono, Courier New, Courier, monospace" style="font-size:10.6667px">>
</font><font face="arial, sans-serif" style="">Users must have created an SSO session to get to that first link inside the student portal, and I've verified SSO to other services without forcing re-authentication. ForceAuthn is "false" for the two requests
as indicated in snippets above. Nevertheless, users generally have to re-authenticate to our institutional IdP for that second service.
</font><font face="arial, sans-serif" style="">I wondered if some process involved in that cascade of saml requests destroyed or invalidated the SSO session cookie. But I verified that after the demand for re-authentication, but prior to re-authenticating,
other SSO-enabled service all work as expected, relying on the initial SSO session used to sign in to the student portal. The behavior described is not consistent - generally re-authentication is required in Chrome, but not in Firefox, and sometimes yes, sometimes
no in a Chrome incognito window. Users and administrators rightly object to this behavior and want SSO to be honored. I won't poison the well with my unfounded speculations, instead asking for your constructive ideas on how to track this down. (Yes, we've
asked the vendor, who has so far responded with crickets.) </font><font style=""><font face="SFMono-Regular, Menlo, Monaco, Consolas, Lucida Console, Liberation Mono, Courier New, Courier, monospace" style="font-size:10.6667px"></font><font face="arial, sans-serif" style="">David
St Pierre Bantz</font></font></span></span>
<div><span class="x_gmail-hljs-tag" style=""><span class="x_gmail-hljs-tag" style=""><font face="arial, sans-serif" style="">UA IAM</font></span></span></div>
</div>
</div>
</div>
</body>
</html>