On 7/23/09 4:22 PM, Cory Snavely wrote:
> FWIW, in our experience, loops like this have been caused by
>
> * Cosign cert not authorized by Cosign server
> * /cosign/valid directory forbidden
>    

I'm working with Joe on the problem. It's not cert based, but from my 
browser's header tracing, more likely related to bad /cosign/valid 
location processing (the appropriate actions are not happening for the 
GET of /cosign/valid).

I'm getting reports of issues with Apache sites that, under Cosign v2, 
used to be able to just process the web site uniformly. Under v3 you 
need to "punch a hole" in the config for /cosign/valid.  Configs like

    * Reverse proxy
    * Entire sites mapped to Drupal, Plone, etc. via ReWrite rules

-Phil Pishioneri
Penn State

------------------------------------------------------------------------------
_______________________________________________
Cosign-discuss mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/cosign-discuss

Reply via email to