<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40"><head><meta http-equiv=Content-Type content="text/html; charset=us-ascii"><meta name=Generator content="Microsoft Word 14 (filtered medium)"><style><!--
/* Font Definitions */
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
span.EmailStyle17
        {mso-style-type:personal-compose;
        font-family:"Calibri","sans-serif";
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-family:"Calibri","sans-serif";}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]--></head><body lang=EN-US link=blue vlink=purple><div class=WordSection1><p class=MsoNormal>We have an IdP that is behind a Cisco Load balancer (two servers)….when only one server is up, everything is fine, but when both servers are active I get a failure. If I’m understanding correctly, the second machine (for the SOAP call) doesn’t know what the transient identifier is and fails. This is only happening against a certain SP, is this a configuration issue, can it be resolved at the load balancer with cookies, or is this where Terracotta comes in?<o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal>One server logs show:<o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal>10:52:44.856 - DEBUG [edu.internet2.middleware.shibboleth.common.attribute.resolver.provider.attributeDefinition.TransientIdAttributeDefinition:97] - Building transient ID for request null; outbound message issuer: https://shibdev.umaryland.edu/idp/shibboleth, inbound message issuer: https://libraries.umd.edu/pdst-hs/sp, principal identifer: brent<o:p></o:p></p><p class=MsoNormal>10:52:44.856 - DEBUG [edu.internet2.middleware.shibboleth.common.attribute.resolver.provider.attributeDefinition.TransientIdAttributeDefinition:115] - Created transient ID _28edc2119a5448b0e2f8a2943fb8ebe9 for request null<o:p></o:p></p><p class=MsoNormal>…<o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal>The other server shows:<o:p></o:p></p><p class=MsoNormal>10:52:45.137 - INFO [Shibboleth-Access:74] - 20130107T155245Z|129.2.19.180|shibdev.umaryland.edu:8443|/profile/SAML1/SOAP/AttributeQuery|<o:p></o:p></p><p class=MsoNormal>10:52:45.139 - INFO [org.opensaml.common.binding.security.SAMLProtocolMessageXMLSignatureSecurityPolicyRule:100] - SAML protocol message was not signed, skipping XML signature processing<o:p></o:p></p><p class=MsoNormal>10:52:45.140 - INFO [org.opensaml.ws.security.provider.ClientCertAuthRule:153] - Authentication via client certificate succeeded for context presenter entity ID: https://libraries.umd.edu/pdst-hs/sp<o:p></o:p></p><p class=MsoNormal>10:52:45.141 - DEBUG [edu.internet2.middleware.shibboleth.common.attribute.resolver.provider.ShibbolethAttributeResolver:201] - Resolving principal name from name identifier of format: urn:mace:shibboleth:1.0:nameIdentifier<o:p></o:p></p><p class=MsoNormal>10:52:45.141 - DEBUG [edu.internet2.middleware.shibboleth.common.attribute.resolver.provider.ShibbolethAttributeResolver:222] - Using principal connector shibTransient to resolve principal name.<o:p></o:p></p><p class=MsoNormal>10:52:45.141 - WARN [edu.internet2.middleware.shibboleth.idp.profile.saml1.AbstractSAML1ProfileHandler:563] - Error resolving principal name for SAML request from relying party 'https://libraries.umd.edu/pdst-hs/sp'. Cause: No information associated with transient identifier: _28edc2119a5448b0e2f8a2943fb8ebe9<o:p></o:p></p><p class=MsoNormal>10:52:45.143 - INFO [Shibboleth-Audit:711] - 20130107T155245Z|urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding|_087209f53983cc23e56287cfe808a64b|https://libraries.umd.edu/pdst-hs/sp|urn:mace:shibboleth:2.0:profiles:saml1:query:attribute|https://shibdev.umaryland.edu/idp/shibboleth|urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding|_6ebe7974192f5318fc6f6d5c37f76856||||||<o:p></o:p></p></div></body></html>