IdP 3 and Stale Requests
James Gross
JamesGross at uncc.edu
Mon Nov 9 10:59:29 EST 2015
Scott,
I appreciate your response. The basis for the back button exclusion, as
well as excluding an improper bookmark is that our service desk remote
accessed the clients machines and performed the steps themselves, including
clearing the cache, restarting the browser and restarting the machine. They
accessed the services by the standard manual typing of the URL for the
service directly into the address bar. We had them perform the steps using
the network inspector so they were able to grab the SAMLRequest directly
from the URL and provide to us for decoding.
One point of clarification I just received is that they are presented with
the Stale Request error immediately AFTER they put in their credentials and
submit the form.
We are using the following configurations for storage, if that matters.
idp.storage.StorageService = org.opensaml.storage.impl.MemoryStorageService
idp.session.StorageService = shibboleth.MemcachedStorageService
idp.cas.StorageService = shibboleth.MemcachedStorageService
------------------------------
*James Gross* | Enterprise Application and CMS Developer (Enterprise Web
Services)
UNC Charlotte | Information Technology Services
9201 University City Blvd. | Charlotte, NC 28223
Phone: 704-687-0298 | Office: Kennedy 301-C39
jgross15 at uncc.edu | http://www.uncc.edu
------------------------------
If you are not the intended recipient of this transmission or a person
responsible for delivering it to the intended recipient, any disclosure,
copying, distribution, or other use of any of the information in this
transmission is strictly prohibited. If you have received this transmission
in error, please notify me immediately by reply e-mail or by telephone at
704-687-0298. Thank you.
On Mon, Nov 9, 2015 at 10:41 AM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> On 11/9/15, 10:31 AM, "users on behalf of James Gross" <
> users-bounces at shibboleth.net on behalf of JamesGross at uncc.edu> wrote:
>
>
>
> >In the logs, we only see the errors "No SAMLRequest or SAMLResponse query
> path parameter, invalid SAML 2 HTTP Redirect message".
>
> That is a back button or bookmark or what not.
>
> > We have confirmed by capture and decoding of the request that the
> SAMLRequest parameter was indeed present and valid.
>
> That, essentially, isn’t possible, at least not with respect to those log
> entries. Of course, there isn’t really a direct correlation possible apart
> from IP.
>
> On what basis did you conclude that they aren’t just hitting the back
> button?
>
> -- Scott
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20151109/9c118ad5/attachment-0001.html>
More information about the users
mailing list