SP always redirect to IdP

Per Jørgen Vigdal Per.Jorgen.Vigdal at evry.com
Thu Nov 5 04:24:57 EST 2015


Thank you, your assumption that it is the IP that changes is the case !
It turns out that we have a BigIP in front that do some NAT address translation.
Is it possible to "turn of" the invalidating of the session when the ip is changing ?

We are migrating from OpenAM to Shibboleth and I do not think we had this issue on OpenAM

Thanks.



-----Original Message-----
From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Cantor, Scott
Sent: 4. november 2015 16:29
To: Shib Users
Subject: Re: SP always redirect to IdP

On 11/4/15, 3:59 AM, "users on behalf of Per Jørgen Vigdal" <users-bounces at shibboleth.net on behalf of Per.Jorgen.Vigdal at evry.com> wrote:



>I cannot find out on what grounds the SP are doing a "re sending" of  AuthnRequest.
>From the log it appears to be related to this line INFO 
>Shibboleth.SessionCache [6]: removed session 
>(_f7761c9408141f6e4c2d74e57f0f0245)
>I am using default values on SP for all timeout values, and it seems that a new AuthnRequest is sent every 30 seconds. I would like to make this period longer. How can I achieve that?

Fix whatever is invalidating the sessions I guess.

Check all the logs, something is there. Probably IP addresses changing I suppose.

-- Scott

--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list