Stale session errors after upgrading to 5.2.2

Wessel, Keith kwessel at illinois.edu
Wed May 20 17:31:42 UTC 2026


Hi, all,

Yesterday, we upgraded our production IdP from 5.1.6 to 5.2.2using the latest I2 image. Other than switching to the new built-in claim to ACR translation functionality, we haven't changed anything else with this upgrade.

This morning, we're seeing a few (but not many) reports of users getting stale session errors when logging into Shib-protected services after getting returned from Entra to the IdP. These users don't seem to be spending an unusual amount of time logging in. Some report that they can get in for some services in some tabs, but when they open another tab after a few minutes, they get the error. I've been able to reproduce this fairly consistently with Chrome in a private browsing window, taking more than 2 minutes to get through Entra. If I go faster through Entra, I don't seem to get the error. We've also managed to reproduce the error in a regular Chrome window, logging into a service, waiting a few minutes, then logging into another.

We don't see any glaring changes in the release notes between 5.1.6 and 5.2.2. Any thoughts on what could be going on here?

Only log message we see here is the usual:

ERROR [net.shibboleth.idp.authn.ExternalAuthenticationException:144] -  [session=218513126E95EE7067FC8A3CDBC23D78] [ip=redacted] net.shibboleth.idp.authn.ExternalAuthenticationException: Error retrieving flow conversationat net.shibboleth.idp.authn.ExternalAuthentication.getProfileRequestContext(ExternalAuthentication.java:248)Caused by: org.springframework.webflow.execution.repository.NoSuchFlowExecutionException: No flow execution could be found with key 'e4s1' -- perhaps this executing flow has ended or expired?

We rolled our sandbox back to 5.1.6 and couldn't replicate the problem on the older version. We're planning to roll back our production IdP but would love to avoid that if possible.

Keith



More information about the users mailing list