Kubernetes and Shibboleth - Client IP Changing - Session Persistence not working

Les LaCroix llacroix at carleton.edu
Tue Mar 26 20:25:07 EDT 2019


Have you configured session affinity?

https://cloud.google.com/load-balancing/docs/backend-service#session_affinity


On Tue, Mar 26, 2019 at 6:54 PM Melvin Lasky <melvin.lasky at manhattan.edu>
wrote:

> Hey everyone,
> We are very close to launching our SHIBBOLETH authentication on Google
> Kubernetes Engine. We are having a slight problem. Our session persistence
> is not working as it should.
>
> You can go to a few services, and then try again, and eventually the login
> page will come up and you’ll have to login again. This happens in < 1
> minute generally of just bouncing around. I set my time-outs to 8 hours,
> and a 2hour idle…
>
> That didn’t fix it. I noticed this in the logs:
>
> shib-idp;idp-process.log;dev;nothing;2019-03-26 23:48:59,282 - WARN
> [net.shibboleth.idp.session.AbstractIdPSession:374] - Client address is
> 10.100.x.x but session
> fdfdf782f30382fa94db9927e745292eb15c039c816f312bebc484d5707181aa already
> bound to 10.12.1.1
> shib-idp;idp-warn.log;dev;nothing;2019-03-26 23:48:59,282 - WARN
> [net.shibboleth.idp.session.AbstractIdPSession:374] - Client address is
> 10.100.x.x but session
> fdfdf782f30382fa94db9927e745292eb15c039c816f312bebc484d5707181aa already
> bound to 10.12.1.1
> shib-idp;idp-process.log;dev;nothing;2019-03-26 23:48:59,291 - WARN
> [net.shibboleth.idp.session.AbstractIdPSession:374] - Client address is
> 10.100.x.x but session
> fdfdf782f30382fa94db9927e745292eb15c039c816f312bebc484d5707181aa already
> bound to 10.12.1.1
> shib-idp;idp-warn.log;dev;nothing;2019-03-26 23:48:59,291 - WARN
> [net.shibboleth.idp.session.AbstractIdPSession:374] - Client address is
> 10.100.x.x but session
> fdfdf782f30382fa94db9927e745292eb15c039c816f312bebc484d5707181aa already
> bound to 10.12.1.1
>
> Now as mentioned, we are using Google Kubernetes Engine. The 10.100.x.x is
> an internal google IP for the compute engine that’s running the cluster.
>
> The 10.12.1.1 address must be coming from the pod, but the pod’s IP is
> 10.12.1.x (with x being a higher number than 1)
>
> Anyhow, does anyone have any suggestions on how we can resolve this issue?
>
> Thanks for all your help!
>
> *Melvin Lasky*
> *Associate Director of Enterprise Architecture*
>
>
>
>
> Riverdale, NY 10471
> Phone: 718-862-7410
> melvin.lasky at manhattan.edu
> www.manhattan.edu
>
>
>
>
> --
> For Consortium Member technical support, see
> https://wiki.shibboleth.net/confluence/x/coFAAg
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20190326/fa6ecf4d/attachment.html>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: email_logo.jpg
Type: image/jpeg
Size: 7478 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/users/attachments/20190326/fa6ecf4d/attachment.jpg>


More information about the users mailing list