SLO: SessionNotFound

Martin Haase Martin.Haase at DAASI.de
Thu Apr 20 05:09:41 EDT 2017


Hi list,

this Is IdP 3.3.0 and SP 2.6.0 on CentOS, openjdk version "1.8.0_121".
We are experiencing a lot of "SessionNotFound" errors from the IdP upon
SAML2 SLO. From what we can see, shortly after authentication, Front
Channel Logout initiated by the SP works, but approx 1 hour after
authentication, the IdP cannot find the SP's session anymore. We upped
all corresponding parameters in idp.properties, to no avail:

< idp.storage.htmlLocalStorage = true
< idp.session.timeout = PT8H
< idp.session.slop = PT4H
< idp.session.trackSPSessions = true
< idp.session.secondaryServiceIndex = true
< idp.session.defaultSPlifetime = PT8H

Do you have a clue why this is? Would it help to move to server-side
session storage?

Regards,

Martin


-- 
Dr. Martin Haase, Solutions Engineer

DAASI International GmbH        
Europaplatz 3                   
D-72072 Tübingen                
Germany                    

phone: +49 7071 407109-0
fax:   +49 7071 407109-9  
email: martin.haase at daasi.de
web:   www.daasi.de

Sitz der Gesellschaft: Tübingen
Registergericht: Amtsgericht Stuttgart, HRB 382175
Geschäftsleitung: Peter Gietz


-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 2247 bytes
Desc: S/MIME Cryptographic Signature
URL: <http://shibboleth.net/pipermail/users/attachments/20170420/651f7078/attachment.p7s>


More information about the users mailing list