Disable SSO session
Andrew Morgan
morgan at orst.edu
Thu Jan 7 14:48:46 EST 2016
On Thu, 7 Jan 2016, Cantor, Scott wrote:
>> I tried this in idp.properties:
>>
>> # Set to false to disable the IdP session layer
>> idp.session.enabled = false
>>
>> but I'm still seeing the SSO session used.
>
> That's how you do it.
Hmmm, that's not the behavior I'm seeing here.
>From my Apache access logs, here is my very first authentication attempt:
10.214.121.42 - - [07/Jan/2016:11:27:47 -0800] "GET /idp/profile/SAML2/Redirect/SSO?SAMLRequest=fVLJTsMwEL0j8Q%2BW79kqRMFqggoIUYklagMHbo4zCa4cT%2FA4Lfw9aQoCDvT6%2FOYt45ldvLeGbcCRRpvyJIw5A6uw0rZJ%2BVNxE5zxi%2Bz4aEayNZ2Y9%2F7VLuGtB%2FJsmLQkxoeU984KlKRJWNkCCa%2FEan5%2FJyZhLDqHHhUazhbXKZeNhbrTXQlWl51Zl1XbmLVSEm27bkpVrmvoaiw5e%2F6ONdnFWhD1sLDkpfUDFCenQZwE8bRIzsVkKk6mL5zlX06X2u4bHIpV7kkkbosiD%2FLHVTEKbHQF7mFgp7xBbAyECtudfS6J9GaAa2kIOJsTgfNDwCu01LfgVuA2WsHT8i7lr953JKJou92GPzKRjNBBg7sWHkKo%2Bkgq4tm4XjE2dL%2F2eji%2F%2FPbn2SGHWfRLPPv6yF2%2FxXWORqsPNjcGt1cOhoGUe9cP3W7QtdL%2F75%2BEyYjoKqhHqugtdaB0raHiLMr2rn8vZrijTw%3D%3D&RelayState=https%3A%2F%2Fwww.google.com%2Fa%2Foregonstate.edu%2FServiceLogin%3Fservice%3Dwise%26passive%3Dtrue%26continue%3Dhttps%253A%252F%252Fdrive.google.com%252Fa%252Foregonstate.edu%252F%253Furp%253Dhttp%25253A%25252F%25252Fmain.oregonstate.edu%25252Fgoogle-apps-osu%2523%26followup%3Dhttps%253A%252F%252Fdrive.google.com%252Fa%252Foregonstate.edu%252F%253Furp%253Dhttp%25253A
%25252F%25252Fmain.oregonstate.edu%25252Fgoogle-apps-osu%26ltmpl%3Ddrive HTTP/1.1" 302 5547
10.214.121.42 - - [07/Jan/2016:11:27:47 -0800] "GET /idp/profile/SAML2/Redirect/SSO;jsessionid=A441E796C168D04C80D405D21C32EECF?execution=e1s1 HTTP/1.1" 302 300
10.214.121.42 - - [07/Jan/2016:11:27:47 -0800] "GET /idp/Authn/RemoteUser?conversation=e1s1 HTTP/1.1" 302 339
10.214.121.42 - - [07/Jan/2016:11:27:47 -0800] "GET /cas/login?service=https%3A%2F%2Flogin.oregonstate.edu%2Fidp%2FAuthn%2FRemoteUser%3Fconversation%3De1s1 HTTP/1.1" 200 2974
10.214.121.42 - - [07/Jan/2016:11:27:52 -0800] "POST /cas/login;jsessionid=4133C152384140C3E474A1FBE4FB4AE9?service=https%3A%2F%2Flogin.oregonstate.edu%2Fidp%2FAuthn%2FRemoteUser%3Fconversation%3De1s1 HTTP/1.1" 302 605
128.193.4.141 - - [07/Jan/2016:11:27:52 -0800] "GET /cas/serviceValidate?ticket=ST-4-9Avts9QZVOH69U2MJbPs-login2&service=https%3A%2F%2Flogin.oregonstate.edu%2Fidp%2FAuthn%2FRemoteUser%3Fconversation%3De1s1 HTTP/1.1" 200 5760
10.214.121.42 - - [07/Jan/2016:11:27:52 -0800] "GET /idp/Authn/RemoteUser?conversation=e1s1&ticket=ST-4-9Avts9QZVOH69U2MJbPs-login2 HTTP/1.1" 302 275
10.214.121.42 - - [07/Jan/2016:11:27:52 -0800] "GET /idp/Authn/RemoteUser?conversation=e1s1 HTTP/1.1" 302 345
10.214.121.42 - - [07/Jan/2016:11:27:52 -0800] "GET /idp/profile/SAML2/Redirect/SSO;jsessionid=A441E796C168D04C80D405D21C32EECF?execution=e1s1&_eventId_proceed=1 HTTP/1.1" 200 4362
You can see it redirect me to CAS, then I authenticate to CAS, then I'm
redirected back to Shibboleth and the SAML response is generated.
About a minute later, I attempt to login to a different SP:
10.214.121.42 - - [07/Jan/2016:11:28:44 -0800] "GET /idp/profile/SAML2/Redirect/SSO?SAMLRequest=nZNdT8IwFIbv%2FRVL72EfDJWGkSDGSOLHAtMLb0xpT7XJ1s6eTvHf2w00JCgxXDU7Oz3vs%2Fc9GyOryppOG%2FeqF%2FDWALpgXZUaafciI43V1DBUSDWrAKnjdDm9vaFJP6K1Nc5wU5JgfpkRMRicnsl0GCWCiziRgxQYSBmthkymPAY5FKlM5Uick%2BARLCqjM%2BLH%2BNuIDcw1OqadL0XxaS%2BKe9FZEY9ock7T9IkE%2BVbrQmmh9MthsNWmCel1UeS9%2FH5ZkGCKCNZ50ZnR2FRgl2DfFYeHxU1GXp2rkYahsfBiWhAHfeVP23DXWOhzU4WtIc98c5lMxu0j7cjtjmOHudg3A5m0iv8QTMbhjtDkZLzJ686Pnl%2FmplT885i8roytmPu7O%2B7HXUWJnuxaaaOxBq6kAuG9LEvzMbPgqTPimVs%2Fwn2yH9ztZoHo9swH4GB91J7NTFUzq7BdHVgz7r6D2B08K73PC5DHxHKwjVPejvbl3B8fxop2K4H7Dyss8wYZ67Z5%2Fcbz49Gvdnizwv2fcfIF HTTP/1.1" 302 445
10.214.121.42 - - [07/Jan/2016:11:28:44 -0800] "GET /idp/profile/SAML2/Redirect/SSO?execution=e2s1 HTTP/1.1" 302 300
10.214.121.42 - - [07/Jan/2016:11:28:44 -0800] "GET /idp/Authn/RemoteUser?conversation=e2s1 HTTP/1.1" 302 301
10.214.121.42 - - [07/Jan/2016:11:28:44 -0800] "GET /idp/profile/SAML2/Redirect/SSO?execution=e2s1&_eventId_proceed=1 HTTP/1.1" 200 12199
There is no redirection back through CAS in this case. I notice that the
conversation variable incremented on the second attempt from "e1s1" to
"e2s1".
In logback.xml, I set:
<variable name="idp.loglevel.idp" value="DEBUG" />
The only line containing "session" in the idp-process.log is:
...
2016-01-07 11:28:44,781 - DEBUG [net.shibboleth.idp.authn.AbstractSubjectCanonicalizationAction:226] - Profile Action SimpleSubjectCanonicalization: trimming whitespace of input string 'morgana'
2016-01-07 11:28:44,782 - DEBUG [net.shibboleth.idp.session.impl.DetectIdentitySwitch:148] - Profile Action DetectIdentitySwitch: No previous session found, nothing to do
2016-01-07 11:28:44,783 - DEBUG [net.shibboleth.idp.authn.impl.FinalizeAuthentication:137] - Profile Action FinalizeAuthentication: Canonical principal name was established as 'morgana'
...
Any ideas? I can provide additional information.
Thanks,
Andy
More information about the users
mailing list