<div style="font-family: Helvetica; font-size: 17px; ">Thanks Scott. I guess it might have something to do with Glassfish as well. I wish I can use the environment variables. But the group who managed that is not willing to do that because of the ease of administration and I don't have much say in that.<div><br></div><div>Thanks for the help. At least I know what I can and I cannot do.&nbsp;</div></div>
                <div><div><br></div><div>--&nbsp;</div><div>Xiaoshu Wang</div><div>Sent with <a href="http://www.sparrowmailapp.com/?sig">Sparrow</a></div><div><br></div></div>
                 
                <p style="color: #A0A0A8;">On Tuesday, September 3, 2013 at 9:58 PM, Cantor, Scott wrote:</p>
                <blockquote type="cite" style="border-left-style:solid;border-width:1px;margin-left:0px;padding-left:10px;">
                    <span><div><div><div>On 9/3/13 9:39 PM, "Xiaoshu Wang" &lt;<a href="mailto:xiaoshuw@email.unc.edu">xiaoshuw@email.unc.edu</a>&gt; wrote:</div><div><br></div><blockquote type="cite"><div>Just did a test, hope this might help shine some lights on.</div></blockquote><div><br></div><div>I know nothing about Glassfish, I'm just telling you your basic</div><div>interpretation is off in some way.</div><div><br></div><blockquote type="cite"><div><div>I put in these configuration on glassfish-<a href="http://web.xml">web.xml</a> because without it.</div><div>When sending multiple request, some request is returned back (200 code</div><div>but with an empty response body). My server code never see these requests.</div></div></blockquote><div><br></div><div>If the SP were trying to cause a session to be created, as you were</div><div>suggesting, those would be 302 redirects, not empty responses.</div><div><br></div><blockquote type="cite"><div><div>And all these happens when there is</div><div>a valid shibboleth session. However, turning off these glassfish option,</div><div>then the previous problem is gone.</div></div></blockquote><div><br></div><div>I guess the glassfish code is doing something then, but that isn't</div><div>anything I can speak to.</div><div><br></div><blockquote type="cite"><div><div>&lt;session-config&gt;</div><div>&lt;session-manager persistence-type="replicated"&gt;</div><div>&lt;manager-properties&gt;</div><div>&lt;property name="relaxCacheVersionSemantics" value="true" /&gt;</div><div>&lt;/manager-properties&gt;</div><div>&lt;/session-manager&gt;</div><div>&lt;/session-config&gt; </div></div></blockquote><div><br></div><div>As I think you probably understand, the session referred to there is not</div><div>anything to do with the SP. It doesn't know about Java and it can't</div><div>connect up with that session.</div><div><br></div><div>Perhaps there's a Glassfish bug related to header size and populating all</div><div>those headers causes it to react badly. If using the environment works, as</div><div>it should with any AJP-capable container, then it seems like that's your</div><div>workaround.</div><div><br></div><div>-- Scott</div><div><br></div><div><br></div><div>--</div><div>To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a></div></div></div></span>
                 
                 
                 
                 
                </blockquote>
                 
                <div>
                    <br>
                </div>