IdPv3 Issues with non-closed browsers
Callum Smith
callum at strubi.ox.ac.uk
Tue Sep 15 07:11:26 EDT 2015
Dear Shibboleth Community,
I'm having an issue with IdPv3 specifically with users who never close their browsers (I am guilty of this). When coming to the IdP where you had previously authenticated from the same service 3+hrs previously, the request times out and hits a 500 error. Once the error has popped refreshing the page causes the username/password challenge to happen all fine. Fresh browser login seems to have no problem.
Running latest IdP v3.1.2 on Tomcat 8.
Service sits behind reverse proxy over ajp
OpenJDK 1.7.0_85 on CentOS 5.11
No errors in the logs.
The server does run memcached with a paired node, both nodes have the IdP setup and running, with the second server set up as a hot swap by the front-end reverse proxy. This feels like the potential cause of issues, should I be looking to change the shibboleth storage engine to something on the disk?
The problem comes that the servers in the pair also run an A:A HA pair of the web services and their configuration can't be changed (turning Memcached off would be bad).
Thanks for any input!
Regards,
Callum Smith
Instruct & Strubi Web Developer
University of Oxford
e. callum at strubi.ox.ac.uk
p. +44 (0)1865 2 87782
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20150915/984f8447/attachment-0001.html>
More information about the users
mailing list