Clustering question around external auth

Jay Fowler fowler at
Wed Aug 31 23:01:37 UTC 2022

AWS ALB with 2 targets
Targets include
OS      = RHEL 8.6
jetty   = 9.4.48
idp     = 4.2.1
+ memcached, unicons shibCas module

Authentication is external using Unicon's CAS module.

Scenario: a node goes offline while the client is performing the external
auth. When the session returns, the load balancer has moved the client to
another node, but the following error is seen:

"Sorry, it looks like there is a problem finding your session ... "

Logs show:

2022-08-31 14:42:54,058 - - WARN
[net.unicon.idp.externalauth.ShibcasAuthServlet:88] - Error processing
ShibCas authentication request
net.shibboleth.idp.authn.ExternalAuthenticationException: Error retrieving
flow conversation
Caused by:
No flow execution could be found with key 'e1s2' -- perhaps this executing
flow has ended or expired? This could happen if your users are relying on
browser history (typically via the back button) that references ended flows.
Caused by:
org.springframework.webflow.conversation.NoSuchConversationException: No
conversation could be found with id '1' -- perhaps this conversation has

Is it possible to replicate the flow conversation across a cluster when
external authentication is used? Something like,
idp.authn.ExternalAuthentication.StorageService =

Should I be looking at something else? or is this something that falls into
the,"there is no solution provided to replicate the per-request
conversational state"?

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <>

More information about the users mailing list