No subject
Ted Fisher
tffishe at bgsu.edu
Wed Aug 6 15:53:46 EDT 2014
I have some behavior from our IDP that is not as expected. We have our IDP configured with only one login handler, "RemoteUser", which uses CAS integration to allow CAS to do the actual authentication and return a Service Ticket to the IDP. When we first log in through CAS this works fine and the AuthnRequest redirected to idp/Authn/RemoteUser which then redirects to our CAS server.
But, while the next AuthnRequest does redirect to idp/Authn/RemoteUser, it does not redirect to our CAS server and instead appears to use and existing session. If I delete the JSESSIONID cookie then it does reidrec to our CAs server as it should, which seems to support that the IDP is using and existing session.
We have the PreviousSession LoginHandler commented which I thought was supposed to suppress using a previous session. But, it is not working that way.
Am I misunderstanding how the previous sessions is supposed to work? Is there a way I can force each AuthnRequst to result in contacting the CAS server in order to let it handle the SSO session as we expected?
Thanks.
Ted F. Fisher
Information Technology Services
[Description: BGSU]
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20140806/101eb98e/attachment.html
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image001.gif
Type: image/gif
Size: 2731 bytes
Desc: image001.gif
Url : http://shibboleth.net/pipermail/users/attachments/20140806/101eb98e/attachment.gif
More information about the users
mailing list