<html>
  <head>
    <meta http-equiv="content-type" content="text/html;
      charset=ISO-8859-1">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <font face="Helvetica, Arial, sans-serif">List,<br>
      <br>
      &nbsp;I have searched the archives, and I believe I know what is
      happening, but I<br>
      am asking for some confirmation on my suspicions.</font><br>
    <br>
    &nbsp;We recently put our IDPs behind a pair of ACE 30 load balancers. We
    are<br>
    doing SSL offloading on ports 443 and 8443. We have had some users
    complaining<br>
    that they can no longer get to the sites they could before.<br>
    <br>
    &nbsp;The site in question is using SAML1 to communicate to our IDP, so
    if I understand<br>
    things correctly, that would be on port 8443. Since we are
    "terminating" the request<br>
    at the load balancer, the IDP is basically "rejecting" the request,
    and the attributes are<br>
    not released to the SP.<br>
    <br>
    &nbsp;Would the solution to this problem be to simply turn off the SSL
    offloading on port<br>
    8443 on the load balancer?<br>
    <br>
    Thank you taking the time to read this email.<br>
    <pre class="moz-signature" cols="72">-- 
Ken Hammer
ITS Identity and Access Management
University Of Michigan
Put your hand on a hot stove for a minute, and it seems like an hour. 
Sit with a pretty girl for an hour, and it seems like a minute. That's Relativity.
- Albert Einstein
</pre>
  </body>
</html>