Shibboleth SP 2.5.5 behind Akamai WAF

James W. Anderson jamesanderson at coca-cola.com
Mon Dec 5 13:28:10 EST 2016


Hi,

We have a .NET web application (WS2012, .NET 4.0, Shibboleth SP 2.5.5 for Windows) that works perfectly when users access the site directly, but when we put Akamai edge caching in front of it, the page returns a few elements then all subsequent resources on the page return 302s. If the user refreshes the page it retrieves a few more elements before returning 302s, and so on. After about 10-15 refreshes, the page is complete with no 302s.

The site is hosted at AWS, the domain name points to Akamai and Akamai proxies requests to the site, which is fronted with an Elastic Load Balancer (ELB), which Akamai references by its name:

Client --> Akamai --> ELB --> App Server

Akamai frequently presents different IP addresses to the back end, so we've disabled any address checking in our Sessions element, shown here:

<Sessions timeout="1800" lifetime="28800" relayState="ss:mem" checkAddress="false" consistentAddress="false" handlerSSL="true" cookieProps="https">

Has anyone else experienced this, and do you have any ideas as to why Akamai could be causing this behavior? We've used Akamai to edge cache for thousands of sites without issue, and this behavior is definitely some kind of strange interplay between Akamai and Shibboleth.

Thanks in advance for any help or guidance you can offer.




[cid:image001.png at 01D01537.F005A230]


James W. Anderson
Cloud Infrastructure Architect
The Coca-Cola Company
404.676.4914 Office
770.653.1033 Mobile
404.598.4914 Fax
jamesanderson at coca-cola.com<mailto:jamesanderson at coca-cola.com>





________________________________

CONFIDENTIALITY NOTICE
NOTICE: This message is intended for the use of the individual or entity to which it is addressed and may contain information that is confidential, privileged and exempt from disclosure under applicable law. If the reader of this message is not the intended recipient, you are hereby notified that any printing, copying, dissemination, distribution, disclosure or forwarding of this communication is strictly prohibited. If you have received this communication in error, please contact the sender immediately and delete it from your system. Thank You.

________________________________

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20161205/1f3501ff/attachment-0001.html>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image001.png
Type: image/png
Size: 12779 bytes
Desc: image001.png
URL: <http://shibboleth.net/pipermail/users/attachments/20161205/1f3501ff/attachment-0001.png>


More information about the users mailing list