Shibboleth 2.5 External Auth handler
Christopher J. Hubing
cjh at psu.edu
Thu Aug 2 16:05:04 EDT 2012
On Thu, 2 Aug 2012, Cantor, Scott wrote:
> On 8/2/12 2:22 PM, "Chris Hubing" <cjh at psu.edu> wrote:
>>
>> Here is the log when I try to come in from the web browser with that
>> session. As you can see the session ID matches the one set above. But,
>> why does it remove the session right away and redirect me back to the
>> discovery service? The session hasn't expired as
>> the expiration timestamp above is 8 hours in the future.
>
> The address is 127.0.01, which I'm guessing isn't your client's address.
> Normally if you want it to work you would provide a proxied address header
> and set the SP up to honor that with the REMOTE_ADDR option. Or you'd have
> to turn off the check.
I do have checkAddress="false" in the ApplicationDefaults element, so
the IP address shouldn't matter.
>
>> Any ideas on why it is not honoring the session would be greatly
>> appreciated.
>
> It should be logging the address mismatch in one of the logs.
>
> -- Scott
>
> --
> To unsubscribe from this list send an email to dev-unsubscribe at shibboleth.net
>
______________________________________________________________________
Christopher J. Hubing Information Technology Services
cjh at psu.edu Emerging Technologies
+1 814 865 8772 Pennsylvania State University
http://www.personal.psu.edu/cjh
More information about the dev
mailing list