REFEDS R&S SP reports intermittent failures
cantor.2 at osu.edu
Sun Apr 24 12:14:18 EDT 2016
On 4/23/16, 12:48 AM, "users on behalf of Baron Fujimoto" <users-bounces at shibboleth.net on behalf of baron at hawaii.edu> wrote:
>I'm trying to troubleshoot reported intermittent failures by an REFEDS
>R&S SP (CILogon) by users using our IdP (2.4.4). The SP reports the
>failures are the result of not receiving any attributes for the user.
That's a later version than I would expect to see this particular condition. Earlier versions will definitely issue empty assertions under various conditions involving cookie failure during some of the transition points. A patch was done to detect a missing session at the vulnerable spot and log it, while terminating the request. It isn't a security issue, really, the assertion is completely empty, but it's annoying, so I patched it.
I don't know of any other intermittent behavior that would cause it.
More information about the users