Occasional SAML exception during SP/IdP handshake

Cantor, Scott cantor.2 at osu.edu
Wed Jul 31 10:41:52 EDT 2013


On 7/31/13 10:25 AM, "Saimon Moore" <saimonmoore at gmail.com> wrote:

>I did some further debugging and this only happens if I reattempt auth
>via shibboleth after a previous successfull login (via shibboleth).
>
>If I don't completely clear all my session cookies I always get the
>exception above. If I do clear session cookies then I don't get the
>exception.

There is nothing like what you described under ordinary use.

>I'm unsure wether this issue is due to the existing session in the SP or
>in the IdP.

The SP has nothing whatsoever to do with this.

>If in the IdP is there a url IdP's have I can redirect users to
>invalidate the IdP Session (for my SP only) there?

That also has nothing to do with this.

Request processing at the IdP is up to the IdP. If you send it requests
that result in a protocol failure, that's that. What's causing the error
is up to the IdP admin to look into and resolve if it's not caused by
something the SP is sending it. AuthnFailed in general means that there's
a login handler acting improperly or being used improperly and isn't able
to handle the login process.

-- Scott




More information about the users mailing list