SimpleSAMLphp IdP and SP - Should cookie names be the same?

6 views
Skip to first unread message

arnaldop...@gmail.com

unread,
Jun 8, 2017, 10:30:43 PM6/8/17
to SimpleSAMLphp
What are you trying to do?

I have the cookie domain set as ".test.mydomain.com".

Should the cookie names be the same between "ip.test.mydomain.com" and "test.mydomain.com"?
Should the cookie names be different between "ip.test.mydomain.com" and "test.mydomain.com"?
Does it matter either way?

Jaime Perez Crespo

unread,
Jun 9, 2017, 3:57:31 AM6/9/17
to simple...@googlegroups.com
Hi!
Yes, it does. If the cookie has the same name and is available to both domains, both instances would share the session. However, both SP and IdP are different things and they need different, independent sessions.

Reply all
Reply to author
Forward
0 new messages