SessionNotFound

Martin Haase Martin.Haase at DAASI.de
Thu Apr 20 12:51:16 EDT 2017


Hi Scott,

you hit the nail on the top. There *was* another assertion issued to the
same SP, same user, in between. So the SP issued this AuthNRequest
although I have set timeout and lifetime to both 28800s as well there.
From what I can see in my own logs, the application did not lose its
session. But the SP, and how could it lose its session? And given this
is what happens in the real world, is there a way to handle this
gracefully at the IdP?

Regards

Martin


On 20.04.2017 18:06, Cantor, Scott wrote:
>> shibboleth-2.6.0-2.1.x86_64, CentOS7. Always the same SP.
> But other SPs work after similar lags in time? That seems odd.
>
> The only likely cause then is what I suggested, a second login over top in the same session.
>
>> ... this key matches what has been issued 63 minutes before as a
>> transient NameID to that SP.
> And no other assertions for the same user to the same SP in between?
>
> No real idea. The record it's not finding is pretty explicitly just the back pointer from the SP/NameID combination, it should last plenty long enough.
>
> -- Scott
>
>

-- 
Dr. Martin Haase, Solutions Engineer

DAASI International GmbH        
Europaplatz 3                   
D-72072 Tübingen                
Germany                    

phone: +49 7071 407109-0
fax:   +49 7071 407109-9  
email: martin.haase at daasi.de
web:   www.daasi.de

Sitz der Gesellschaft: Tübingen
Registergericht: Amtsgericht Stuttgart, HRB 382175
Geschäftsleitung: Peter Gietz


-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 2247 bytes
Desc: S/MIME Cryptographic Signature
URL: <http://shibboleth.net/pipermail/users/attachments/20170420/67f4eb97/attachment-0001.p7s>


More information about the users mailing list