Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Expand
titleQ: After login a redirect loop occurs.

A:

M

All persons who will use the VC must be registered through the UNIC VC Portal. After someone registers as a University Admin (UNI Admin), it is necessary to send an email to the University computing Centre (us), to approve them as UNI Admin. Once approved, they will be able to approve other OrgUnit Admins.

From the cookies available for your domain, we have discovered a cookie with invalid SameSite configuration (picture attached). The problem is that the SameSite cookie attribute is not set, while the correct configuration would be SameSite=None. In certain situations, some browsers will discard such cookie when switching between different domains, as is the case in SSO authentication. We believe that this causes problems for some of your users when they are trying to connect to UNIC SP.

Image Added

More on SameSite cookie atribute can be found at: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Set-Cookie/SameSite

Also, ake sure that your Idp delivers the following mandatory eduGain attributes to the UNIC SP:

  • schacHomeOrganization
  • eduPersonScopedAffiliation
  • schacPersonalUniqueCode

...