session not sticky or something else?

Nickles, Brent bnick001 at umaryland.edu
Mon Jan 7 11:13:59 EST 2013


We have an IdP that is behind a Cisco Load balancer (two servers)....when only one server is up, everything is fine, but when both servers are active I get a failure.   If I'm understanding correctly, the second machine (for the SOAP call) doesn't know what the transient identifier is and fails.   This is only happening against a certain SP, is this a configuration issue, can it be resolved at the load balancer with cookies, or is this where Terracotta comes in?

One server logs show:

10:52:44.856 - DEBUG [edu.internet2.middleware.shibboleth.common.attribute.resolver.provider.attributeDefinition.TransientIdAttributeDefinition:97] - Building transient ID for request null; outbound message issuer: https://shibdev.umaryland.edu/idp/shibboleth, inbound message issuer: https://libraries.umd.edu/pdst-hs/sp, principal identifer: brent
10:52:44.856 - DEBUG [edu.internet2.middleware.shibboleth.common.attribute.resolver.provider.attributeDefinition.TransientIdAttributeDefinition:115] - Created transient ID _28edc2119a5448b0e2f8a2943fb8ebe9 for request null
...

The other server shows:
10:52:45.137 - INFO [Shibboleth-Access:74] - 20130107T155245Z|129.2.19.180|shibdev.umaryland.edu:8443|/profile/SAML1/SOAP/AttributeQuery|
10:52:45.139 - INFO [org.opensaml.common.binding.security.SAMLProtocolMessageXMLSignatureSecurityPolicyRule:100] - SAML protocol message was not signed, skipping XML signature processing
10:52:45.140 - INFO [org.opensaml.ws.security.provider.ClientCertAuthRule:153] - Authentication via client certificate succeeded for context presenter entity ID: https://libraries.umd.edu/pdst-hs/sp
10:52:45.141 - DEBUG [edu.internet2.middleware.shibboleth.common.attribute.resolver.provider.ShibbolethAttributeResolver:201] - Resolving principal name from name identifier of format: urn:mace:shibboleth:1.0:nameIdentifier
10:52:45.141 - DEBUG [edu.internet2.middleware.shibboleth.common.attribute.resolver.provider.ShibbolethAttributeResolver:222] - Using principal connector shibTransient to resolve principal name.
10:52:45.141 - WARN [edu.internet2.middleware.shibboleth.idp.profile.saml1.AbstractSAML1ProfileHandler:563] - Error resolving principal name for SAML request from relying party 'https://libraries.umd.edu/pdst-hs/sp'. Cause: No information associated with transient identifier: _28edc2119a5448b0e2f8a2943fb8ebe9
10:52:45.143 - INFO [Shibboleth-Audit:711] - 20130107T155245Z|urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding|_087209f53983cc23e56287cfe808a64b|https://libraries.umd.edu/pdst-hs/sp|urn:mace:shibboleth:2.0:profiles:saml1:query:attribute|https://shibdev.umaryland.edu/idp/shibboleth|urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding|_6ebe7974192f5318fc6f6d5c37f76856||||||
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130107/761b4be4/attachment.html 


More information about the users mailing list