<div dir="ltr">Hi,<div><br></div><div>I did some further debugging and this only happens if I reattempt auth via shibboleth after a previous successfull login (via shibboleth). </div><div><br></div><div>If I don&#39;t completely clear all my session cookies I always get the exception above. If I do clear session cookies then I don&#39;t get the exception.</div>
<div><br></div><div>I&#39;m unsure wether this issue is due to the existing session in the SP or in the IdP.</div><div><br></div><div>From what you&#39;ve said Peter, this looks like it&#39;s due to the session maintained by the IdP.</div>
<div><br></div><div>If on the other hand it&#39;s due to the existing session in the SP then after logging out the user in my application is there anything else I need to do to invalidate the SP session? I have actually tried to redirect to /Shibboleth.sso/Logout but that doesn&#39;t fix the issue so I&#39;m more inclined to believe the issue is with the IdP.</div>
<div><br></div><div>If in the IdP is there a url IdP&#39;s have I can redirect users to invalidate the IdP Session (for my SP only) there?</div><div><br></div><div>For the time being we are recommending users signing in via shibboleth to close their browser upon logout but in this day and age this seems a bit archaic.</div>
<div><br></div><div>Regards,</div><div><br></div><div>Saimon</div><div><br></div><div><br></div></div><div class="gmail_extra"><br><br><div class="gmail_quote">On Fri, Jul 26, 2013 at 11:30 AM, Saimon Moore <span dir="ltr">&lt;<a href="mailto:saimonmoore@gmail.com" target="_blank">saimonmoore@gmail.com</a>&gt;</span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr">Thanks Peter<div><br></div><div>I&#39;ll take it up with the Idp.</div></div><div class="gmail_extra"><div>
<div class="h5"><br><br><div class="gmail_quote">On Fri, Jul 26, 2013 at 11:25 AM, Peter Schober <span dir="ltr">&lt;<a href="mailto:peter.schober@univie.ac.at" target="_blank">peter.schober@univie.ac.at</a>&gt;</span> wrote:<br>

<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">* Peter Schober &lt;<a href="mailto:peter.schober@univie.ac.at" target="_blank">peter.schober@univie.ac.at</a>&gt; [2013-07-26 11:22]:<br>


<div>&gt; &gt;     Error from identity provider:<br>
&gt; &gt;<br>
&gt; &gt;         Status: urn:oasis:names:tc:SAML:2.0:status:Responder<br>
&gt; &gt;         Sub-Status: urn:oasis:names:tc:SAML:2.0:status:AuthnFailed<br>
&gt;<br>
&gt; Well, it clearly says &quot;Error from idrentity provider&quot; and the IdP said<br>
&gt; &quot;authentication unless you&#39;re requesting a specifc authentication<br>
&gt; method from that IDP which the IdP cannot provide, there&#39;s nothing the<br>
&gt; SP can do about it. It&#39;s an error from the IdP, after all.<br>
<br>
</div>Sorry, bad connectivity and typing into a terminal don&#39;t go well<br>
together. Should have been &#39;the IdP said &quot;AuthnFailed&quot;, so unless...&#39;<br>
<div><div>-peter<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br><br clear="all"><div><br></div></div></div><span class="HOEnZb"><font color="#888888">-- <br>Saimon Moore<br>Web Developer @ Teambox.com<br>(<a href="http://teambox.com" target="_blank">http://teambox.com</a>)<br>
<br>Skype: saimonmoore<br>Yahoo IM: saimonmoore<br>
Google IM: saimonmoore
</font></span></div>
</blockquote></div><br><br clear="all"><div><br></div>-- <br>Saimon Moore<br>Web Developer @ Teambox.com<br>(<a href="http://teambox.com" target="_blank">http://teambox.com</a>)<br><br>Skype: saimonmoore<br>Yahoo IM: saimonmoore<br>
Google IM: saimonmoore
</div>