Bug 39473 - Parallel UMC sessions for different ports on the same IP address not possible
Parallel UMC sessions for different ports on the same IP address not possible
Status: CLOSED FIXED
Product: UCS
Classification: Unclassified
Component: Docker
UCS 4.1
Other Linux
: P5 normal (vote)
: UCS 4.1
Assigned To: Florian Best
Alexander Kläser
: interim-2
Depends on: 38344
Blocks: 39918
  Show dependency treegraph
 
Reported: 2015-10-05 12:21 CEST by Florian Best
Modified: 2015-11-17 12:12 CET (History)
2 users (show)

See Also:
What kind of report is it?: ---
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Max CVSS v3 score:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Florian Best univentionstaff 2015-10-05 12:21:22 CEST
This has to be done for the SAML cookies as well.

+++ This bug was initially created as a clone of Bug #38344 +++

... this is a feature which is needed in the docker environment as different instances are accessed via the same IP address and different ports. This is currently not possible, as one single session cookie is stored for a whole domain.
Comment 1 Florian Best univentionstaff 2015-10-05 14:04:35 CEST
univention-management-console-frontend (5.0.29-1):
r64219 | Bug #39473: add cookie suffix in SAML cookies for docker integration
Comment 2 Alexander Kläser univentionstaff 2015-11-12 15:48:13 CET
The current state is as the following:
* Parallel UMC session on different ports are generally possible, e.g., on a UCS
  master and on a UCS container (accessed via a particular port).
* It is _not_ possible to use SAML for logging into the container UMC. The 
  container has no DNS record and its FQDN can thus not be resolved. It would be
  possible, however, if the IdP would respect the initial port for the redirect.

As SAML login for containers is not a must feature at the moment → VERIFIED
Comment 3 Stefan Gohmann univentionstaff 2015-11-17 12:12:03 CET
UCS 4.1 has been released:
 https://docs.software-univention.de/release-notes-4.1-0-en.html
 https://docs.software-univention.de/release-notes-4.1-0-de.html

If this error occurs again, please use "Clone This Bug".