How are the SPConfig clockSkew attribute and a Conditions NotBefore related?

Brian Reindel giantjamsandwich at gmail.com
Mon Jun 23 14:13:17 EDT 2014


"Could be IP address mismatch I guess..."

You may have something there. I noticed on my local of course my IP
address is 127.0.0.1, and it works, but in the logs for our dev server
I'm seeing on this line:

2014-06-23 13:54:48 INFO Shibboleth.SessionCache [2]: new session
created: ID (_fe43b87b9257f9b2030af20e7abcff4e) IdP (URL Redacted)
Protocol(urn:oasis:names:tc:SAML:2.0:protocol) Address (IP Redacted)

That the IP I have redacted is not actually the IP for the virtual
host configured. I'm wondering if that mismatch is causing the
expiration.



On Mon, Jun 23, 2014 at 1:26 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> On 6/23/14, 1:23 PM, "Brian Reindel" <giantjamsandwich at gmail.com> wrote:
>
>>The decrypted assertion has no SessionNotOnOrAfter set. This is the
>>AuthnStatement:
>
> I'm at a loss then, but the cause is not clock skew, lack thereof, etc.
> Once the session's created, invalidating it is a function of policy. Could
> be IP address mismatch I guess. Since the session's invalidating, it's not
> a case of not sending the cookie back correctly, so something else is
> invalid about the request.
>
> -- Scott
>
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list