Strange Shib SP behaviour during service access from UAE

Cantor, Scott cantor.2 at osu.edu
Sun Oct 9 15:31:58 EDT 2016


>     > - When changing webpages within the protected domain/host shib does
> not recognize that I have a valid authenticated session and sends me to the
> discovery service.

The logs will always tell you what it's doing there unless the request doesn't contain the session cookie.

>     > - Sometimes, the web application does not receive authenticated
> attributes from shib even if the assertion contains all attributes (using AJP
> headers).

That's only possible with passive protection rules and just means the request isn't authenticated. There is no other explanation for that.

> Did a trace and the strange thing is:
> - when returning to Shib SP it sets a shibsession cookie.
> - First request to server contains this cookie resulting in 200 OK
> - Second request to server contains shibsession cookie but stops at
> Shibboleth SP who sets a new shibsession cookie and redirects to DS URL.

Then the log will tell you why.

> Wandering if there might be some issue related to different time zones. UAE
> is 2 hours before my server??

No.

-- Scott



More information about the users mailing list