<div dir="ltr"><div>Thanks Scott,<br></div><div><br></div><div>I put on my thinking cap and realised that I had forceAuthn set to true in shib2.xml config and this is why the existing session wasn&#39;t be reused.</div><div>
<br></div><div>So in reality I was asking the idp to reauthenticate while an existing session already existed. It may be that the IdP has an issue with this when the session cookies exist for the user retrying the authentication.</div>
<div><br></div><div>For us this solution is good enough.</div><div><br></div><div>I completely missed this attribute in my previous investigations.</div><div><br></div><div>Thanks and sorry for the noise.</div><div class="gmail_extra">
<br><br><div class="gmail_quote">On Wed, Jul 31, 2013 at 4:41 PM, Cantor, Scott <span dir="ltr">&lt;<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div class="im">On 7/31/13 10:25 AM, &quot;Saimon Moore&quot; &lt;<a href="mailto:saimonmoore@gmail.com">saimonmoore@gmail.com</a>&gt; wrote:<br>
<br>
&gt;I did some further debugging and this only happens if I reattempt auth<br>
&gt;via shibboleth after a previous successfull login (via shibboleth).<br>
&gt;<br>
&gt;If I don&#39;t completely clear all my session cookies I always get the<br>
&gt;exception above. If I do clear session cookies then I don&#39;t get the<br>
&gt;exception.<br>
<br>
</div>There is nothing like what you described under ordinary use.<br>
<div class="im"><br>
&gt;I&#39;m unsure wether this issue is due to the existing session in the SP or<br>
&gt;in the IdP.<br>
<br>
</div>The SP has nothing whatsoever to do with this.<br>
<div class="im"><br>
&gt;If in the IdP is there a url IdP&#39;s have I can redirect users to<br>
&gt;invalidate the IdP Session (for my SP only) there?<br>
<br>
</div>That also has nothing to do with this.<br>
<br>
Request processing at the IdP is up to the IdP. If you send it requests<br>
that result in a protocol failure, that&#39;s that. What&#39;s causing the error<br>
is up to the IdP admin to look into and resolve if it&#39;s not caused by<br>
something the SP is sending it. AuthnFailed in general means that there&#39;s<br>
a login handler acting improperly or being used improperly and isn&#39;t able<br>
to handle the login process.<br>
<span class="HOEnZb"><font color="#888888"><br>
-- Scott<br>
</font></span><div class="HOEnZb"><div class="h5"><br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br><br clear="all"><div><br></div>-- <br>Saimon Moore<br>Web Developer @ Teambox.com<br>(<a href="http://teambox.com" target="_blank">http://teambox.com</a>)<br><br>Skype: saimonmoore<br>Yahoo IM: saimonmoore<br>
Google IM: saimonmoore
</div></div>