Client sent a cookie from address ... but the cookie was issued to address ...
Chad La Joie
lajoie at itumi.biz
Fri Feb 10 17:18:14 GMT 2012
That is part of the IdP's session security mechanism; it checks to
ensure that the client that was given the cookie (as identified by its
IP) is the client that sent it back. That error could be caused by
some one stealing a session cookie or more likely a user that logs in,
physically moves somewhere, gets a new DHCP address and tries to use
their existing session.
>From the user's standpoint they don't get an error, they're just asked
to log in again.
There is a way to shut it off, but I wouldn't recommend it.
On Fri, Feb 10, 2012 at 11:43, Stefano Zanmarchi <zanmarchi at gmail.com> wrote:
> Hi,
> I often get big burst of this error in my idp-process.log, I can't
> understand why.
> Is there a way to avoid it? And does this result in an error page to the user?
--
Chad La Joie
www.itumi.biz
trusted identities, delivered
More information about the users
mailing list