SP always redirect to IdP
Per Jørgen Vigdal
Per.Jorgen.Vigdal at evry.com
Thu Nov 5 04:24:57 EST 2015
Thank you, your assumption that it is the IP that changes is the case !
It turns out that we have a BigIP in front that do some NAT address translation.
Is it possible to "turn of" the invalidating of the session when the ip is changing ?
We are migrating from OpenAM to Shibboleth and I do not think we had this issue on OpenAM
Thanks.
-----Original Message-----
From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Cantor, Scott
Sent: 4. november 2015 16:29
To: Shib Users
Subject: Re: SP always redirect to IdP
On 11/4/15, 3:59 AM, "users on behalf of Per Jørgen Vigdal" <users-bounces at shibboleth.net on behalf of Per.Jorgen.Vigdal at evry.com> wrote:
>I cannot find out on what grounds the SP are doing a "re sending" of AuthnRequest.
>From the log it appears to be related to this line INFO
>Shibboleth.SessionCache [6]: removed session
>(_f7761c9408141f6e4c2d74e57f0f0245)
>I am using default values on SP for all timeout values, and it seems that a new AuthnRequest is sent every 30 seconds. I would like to make this period longer. How can I achieve that?
Fix whatever is invalidating the sessions I guess.
Check all the logs, something is there. Probably IP addresses changing I suppose.
-- Scott
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list