Incorrect (stale) user data in SAML2 assertion
Matthew Slowe
M.Slowe at kent.ac.uk
Thu Mar 12 06:57:58 EDT 2015
We're using Shibboleth IDP inside Tomcat sat behind Apache (with
mod_auth_mellon to do internal SSO) to authenticate users to Office365.
Generally this works fine! :-)
When the user is finished in Office365 they click Sign Out, their Office365
session is destroyed and they're sent off to our local SSO SLO service (which
then handles signing them out of anythign else, including the Apache in front
of the IDP).
Suppose the following:
1) User A browses to SP to initiate a logon
2) User A hits the Shibboleth IDP's webserver, has no SSO session and is sent away to log in
3) User A logs in to SSO and returns to Shibboleth
4) User A hits Shibboleth IDP webserver again and request is proxied to Tomcat with REMOTE_USER set
5) User A is sent off to SP to check their email and is happy
When they're done, User A logs out & SLO reports success! Everything is as it should be.
User B then starts the whole process again within the same browser... if this
happens in a shortish space of time then User B's SAML2 assertion generated by
the Shibboleth IDP for the SP is generated with User A's already resolved
attributes.
Logs below.
1
+-----------+
v |
+----+ 5 +-------------------+ 3 +-----+
| SP | <--- | browser | ---> | SSO |
+----+ +-------------------+ +-----+
| |
| 4 | 2
v |
+-------------+ |
| httpd+authz | <+
+-------------+
|
| 4A
v
+-------------+
| idp |
+-------------+
I tried disabling the PreviousSession Login Handler (https://wiki.shibboleth.net/confluence/display/SHIB2/IdPAuthPreviousSession) to no avail.
I have verified that the REMOTE_USER going over AJP is correctly changing between User A and User B.
Any other ideas?
Thankyou!
foo
=== LOGS (Apache and IDP interleaved) ===
User A logging in
-----------------
1.2.3.4 - - [12/Mar/2015:10:53:00 +0000] "GET /r/ HTTP/1.1" 303 415
1.2.3.4 - - [12/Mar/2015:10:53:00 +0000] "GET /mellon/login?ReturnTo=https%3A%2F%2Fdan.kent.ac.uk<http://2Fdan.kent.ac.uk>%2Fr%2F&IdP=https%3A%2F%2Fsso.id.kent.ac.uk<http://2Fsso.id.kent.ac.uk>%2Fidp HTTP/1.1" 303 1354
1.2.3.4 - - [12/Mar/2015:10:53:06 +0000] "POST /mellon/postResponse HTTP/1.1" 303 314
1.2.3.4 - user_a [12/Mar/2015:10:53:06 +0000] "GET /r/ HTTP/1.1" 302 301
1.2.3.4 - user_a [12/Mar/2015:10:53:07 +0000] "POST /idp-b/profile/SAML2/POST/SSO HTTP/1.1" 302 -
1.2.3.4 - user_a [12/Mar/2015:10:53:07 +0000] "GET /idp-b/AuthnEngine HTTP/1.1" 302 -
1.2.3.4 - user_a [12/Mar/2015:10:53:07 +0000] "GET /idp-b/Authn/RemoteUser HTTP/1.1" 302 -
20150312T105308Z|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST|_7157c1e3-f97a-445e-b475-09b71f37e68e|urn:federation:MicrosoftOnline|urn:mace:shibboleth:2.0:profiles:saml2:sso|https://dan.kent.ac.uk/idp-b/shibboleth|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST|_47824311b39c0156fc1fb87fd035b4f7|user_a|urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport|transientId,UserId,ImmutableID,|tcZvZyqWA0ewAPx4bIxz9g==|_f3863de26771d6dadc81c40f402cfbc0,|
1.2.3.4 - user_a [12/Mar/2015:10:53:07 +0000] "GET /idp-b/profile/SAML2/POST/SSO HTTP/1.1" 200 7840
1.2.3.4 - - [12/Mar/2015:10:53:28 +0000] "GET /mellon/logout?SAMLRequest=<removed> HTTP/1.1" 303 1255
User B logging in
-----------------
1.2.3.4 - - [12/Mar/2015:10:53:31 +0000] "GET /r/ HTTP/1.1" 303 415
1.2.3.4 - - [12/Mar/2015:10:53:31 +0000] "GET /mellon/login?ReturnTo=https%3A%2F%2Fdan.kent.ac.uk<http://2Fdan.kent.ac.uk>%2Fr%2F&IdP=https%3A%2F%2Fsso.id.kent.ac.uk<http://2Fsso.id.kent.ac.uk>%2Fidp HTTP/1.1" 303 1346
1.2.3.4 - - [12/Mar/2015:10:53:33 +0000] "POST /mellon/postResponse HTTP/1.1" 303 314
1.2.3.4 - user_b [12/Mar/2015:10:53:33 +0000] "GET /r/ HTTP/1.1" 302 301
1.2.3.4 - user_b [12/Mar/2015:10:53:34 +0000] "POST /idp-b/profile/SAML2/POST/SSO HTTP/1.1" 302 -
1.2.3.4 - user_b [12/Mar/2015:10:53:34 +0000] "GET /idp-b/AuthnEngine HTTP/1.1" 302 -
1.2.3.4 - user_b [12/Mar/2015:10:53:34 +0000] "GET /idp-b/Authn/RemoteUser HTTP/1.1" 302 -
20150312T105334Z|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST|_afc5a5eb-ab77-44b7-8b7a-e245ea3df925|urn:federation:MicrosoftOnline|urn:mace:shibboleth:2.0:profiles:saml2:sso|https://dan.kent.ac.uk/idp-b/shibboleth|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST|_1ade3c708ffb70646fa4bb580608f32f|user_a|urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport|transientId,UserId,ImmutableID,|tcZvZyqWA0ewAPx4bIxz9g==|_959cdc3f5ecd22e17a7f5effd5e8be1f,|
1.2.3.4 - user_b [12/Mar/2015:10:53:34 +0000] "GET /idp-b/profile/SAML2/POST/SSO HTTP/1.1" 200 7830
Note how in the IDP audit log line it is user_a being returned...
--
Matthew Slowe | Server Infrastructure Officer
IT Infrastructure, Information Services, University of Kent
Room S21, Cornwallis South
Canterbury, Kent, CT2 7NZ, UK
Tel: +44 (0)1227 824265
www.kent.ac.uk/is<http://www.kent.ac.uk/is> | @UnikentUnseenIT | @UKCLibraryIt
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20150312/8ac4db6e/attachment.html
More information about the users
mailing list