Expired session not posting saml after idp redirect

JamesP jcparsons at gmail.com
Tue Oct 16 00:05:57 EDT 2018


Hi All,
we have a Shib SP 2.6 deployed on Apache 2.4 proxy front ending the
application.  We have an issue where once the shib session is expired (most
users leave their app tabs open all day, or hibernate/sleep and try to
resume the next day) and a user tries to click on app objects/links, we can
see that the browser gets redirected to the IdP, but on redirect back to
apache the browser is not getting sent to "/Shibboleth.sso/SAML2/POST", it
is sent back to the resource it asked to access.  hence can see no shib
session cookie.  users keep clicking on stuff and as expected each click
gets redirected for IdP authentication.  Essentially browser/app session is
stale and the only thing to fix it is doing a refresh on the page.

Our realm on the IdP does not have an application location/URL set as we are
hosting multiple apps on the same apache proxy host.  so the vhost
servername that redirects to the  IdP, is what the IdP uses for the redirect
back

any ideas on why it's not posting back to the /Shibboleth.sso/SAML2/POST? or
how to handle the expired session so it starts the process from the
beginning?

thanks
James



--
Sent from: http://shibboleth.1660669.n2.nabble.com/Shibboleth-Users-f1660767.html


More information about the users mailing list