IdP only using HTTP-Redirect binding
Rawlinson, Philip (rawlinpa)
RAWLINPA at UCMAIL.UC.EDU
Thu Sep 27 15:30:33 EDT 2012
We took an IdP that has been working fine for over a year and cloned that Linux server to use as a starting point for a second IdP. This second server has a couple of differences in configuration now, which were increasing the shibboleth.SessionManager value and adding back in the PreviousSession LoginHandler (it was removed from the original IdP). Everything appeared to be working, but one external SP reported an issue. Looking at idp-process.log and idp-audit.log, we noticed that the second IdP is only ever doing HTTP-Redirect bindings, while the original IdP shows requests with additional bindings too as expected. Tests with that external SP found that on the original IdP, first it will do the HTTP-Redirect binding and then a SOAP binding. On the second IdP, it only does the HTTP-Redirect binding. There are no errors in the logs, but the original IdP has this line and the second IdP does not:
DEBUG [edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler:163] - Incoming request contains a login context, processing as second leg of request
So we have two IdPs, which are pretty close to identical, but the second one is only doing HTTP-Redirect bindings.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20120927/efdfa97d/attachment.html
More information about the users
mailing list