Address mismatch after authentication, with IPv6 enabled
joller lee
joller.lee at gmail.com
Tue Aug 29 01:29:56 EDT 2017
I've deployed Shibboleth IdP (3.2.1) and SP (2.6.0, IIS 7) without any
problem,
until I enabled IPv6 on the client PC, IdP, web server(with SP), and the
DNS server.
I'm getting error message as follows:
opensaml::FatalProfileException at (
https://www.xxx.xxx.xx/Shibboleth.sso/SAML2/POST)
Your client's current address (wwww:xxxx:yyyy:zzzz::eeee) differs from the
one used when you authenticated to your identity provider. To correct this
problem, you may need to bypass a proxy server. Please contact your local
support staff or help desk for assistance.
With assistance of Wireshark, I'm sure the client PC visits IdP and SP with
IPv6.
The logs on IdP and SP reveal that the addresses observed by IdP and SP are
the same,
except that IdP seems to use the full form (ie. with zero's preserved)
while SP the abbreviated one.
Any idea about the possible cause?
How can I survey this problem further?
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170829/4927983f/attachment-0001.html>
More information about the users
mailing list