REFEDS R&S SP reports intermittent failures

Cantor, Scott cantor.2 at
Sun Apr 24 12:14:18 EDT 2016

On 4/23/16, 12:48 AM, "users on behalf of Baron Fujimoto" <users-bounces at on behalf of baron at> wrote:

>I'm trying to troubleshoot reported intermittent failures by an REFEDS
>R&S SP (CILogon) by users using our IdP (2.4.4). The SP reports the
>failures are the result of not receiving any attributes for the user.

That's a later version than I would expect to see this particular condition. Earlier versions will definitely issue empty assertions under various conditions involving cookie failure during some of the transition points. A patch was done to detect a missing session at the vulnerable spot and log it, while terminating the request. It isn't a security issue, really, the assertion is completely empty, but it's annoying, so I patched it.

I don't know of any other intermittent behavior that would cause it.

-- Scott

More information about the users mailing list