<html>
  <head>

    <meta http-equiv="content-type" content="text/html; charset=ISO-8859-1">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    I am running Alfresco, an open source web based ECM, behind
    Shibboleth (Apache 2). Alfresco has quite a few XML HTTP requests
    (AJAX). Occasionally, we can't discern any reason as to when, we are
    seeing a page fail to completely load. When this happens it appears
    that the session has been dropped on the SP side and the SP fails to
    send a SAML POST to the IDP. I have exhausted my (limited) knowledge
    on the subject and could really use some help troubleshooting the
    issue.<br>
    <br>
    On failure, the shibd.log on the SP has (identifying information
    removed):<br>
    2014-09-04 07:46:58 INFO Shibboleth.SessionCache [3]: new session
    created: ID (_8afc83602ee907b1e83992c61fef98dd) IdP
    (<a class="moz-txt-link-freetext" href="https://idp.domain.com/">https://idp.domain.com/</a>)
    Protocol(urn:oasis:names:tc:SAML:2.0:protocol) Address (10.0.135.18)<br>
    2014-09-04 07:46:58 DEBUG Shibboleth.SSO.SAML2 [3]: ACS returning
    via redirect to: <a class="moz-txt-link-freetext" href="https://server.domain.com/share/page/repository">https://server.domain.com/share/page/repository</a><br>
    2014-09-04 07:47:59 INFO Shibboleth.SessionCache [6]: removed
    session (_8afc83602ee907b1e83992c61fef98dd)<br>
    2014-09-04 07:47:59 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [6]:
    validating input<br>
    2014-09-04 07:47:59 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [6]:
    marshalling, deflating, base64-encoding the message<br>
    2014-09-04 07:47:59 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [6]:
    marshalled message:<br>
    ...&lt;cut&gt;<br>
    2014-09-04 07:47:59 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [6]:
    message encoded, sending redirect to client<br>
    2014-09-04 07:47:59 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [6]:
    validating input<br>
    2014-09-04 07:47:59 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [6]:
    marshalling, deflating, base64-encoding the message<br>
    2014-09-04 07:47:59 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [6]:
    marshalled message:<br>
    <br>
    I notice that a "normal" successful interaction is more like this
    (note the SAML2POST):<br>
    2014-09-04 11:39:24 INFO Shibboleth.SessionCache [2]: removed
    session (_32645b3099cdfa688622954b1ac4a8c9)<br>
    2014-09-04 11:39:24 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [2]:
    validating input<br>
    2014-09-04 11:39:24 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [2]:
    marshalling, deflating, base64-encoding the message<br>
    2014-09-04 11:39:24 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [2]:
    marshalled message:<br>
    ...&lt;cut&gt;<br>
    2014-09-04 11:39:24 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [2]:
    message encoded, sending redirect to client<br>
    2014-09-04 11:39:27 DEBUG OpenSAML.MessageDecoder.SAML2POST [1]:
    validating input<br>
    2014-09-04 11:39:27 DEBUG OpenSAML.MessageDecoder.SAML2POST [1]:
    decoded SAML message:<br>
    ...&lt;cut&gt;<br>
    <br>
    The failed authentication shows the following on the IdP side:<br>
    15:29:32.931 - WARN
    [edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler:371]
    - Error decoding authentication request message
    <br>
    org.opensaml.ws.message.decoder.MessageDecodingException: No
    SAMLRequest or SAMLResponse query path parameter, invalid SAML 2
    HTTP Redirect message
    <br>
    <br>
    The end result is errors like this in the browser:<br>
    <span style="box-sizing: border-box; color: rgb(255, 0, 0);
      font-family: Consolas, 'Lucida Console', monospace; font-size:
      12px; font-style: normal; font-variant: normal; font-weight:
      normal; letter-spacing: normal; line-height: normal; orphans:
      auto; text-align: start; text-indent: 0px; text-transform: none;
      white-space: pre-wrap; widows: auto; word-spacing: 0px;
      -webkit-text-stroke-width: 0px; background-color: rgb(255, 255,
      255);">XMLHttpRequest cannot load <a
href="https://idp.stanford.edu/idp/profile/SAML2/Redirect/SSO?SAMLRequest=hZLNbsIwEIRfJfKdOBhowSKRUjgUiRZEaA%2B9VE68AUuOnXqd%2Frx9A6EtXOjVnv1mZ7RTFJWuedr4vdnAWwPog89KG%2BTHj5g0znArUCE3ogLkvuBZ%2BrDkLIx47ay3hdUkSBHBeWXNzBpsKnAZuHdVwNNmGZO99zVySneY9wprPBgfohemtE6GIBua7VWeWw1%2BHyJaeuAzul5lWxLM24WUEQf0H0jJ%2BhLQPtB2mVJpOE1vQCoHhadZtiLBYh6TVzES8lbmw9GgLEsW5QDsBkZSjpkcDFk5aWWIDSzMAe1jwqL%2BsBdNetFgyxjvMx6NX0iwPmW%2BU0Yqs7teUN6JkN9vt%2Btel%2BgZHB7TtAKSTA8186OxOyv%2BOlb8tE2Sf7vF326n9MyrM675YwtfzNdWq%2BIrSLW2HzMHwkNM%2BoQm3cjleSTf&amp;RelayState=ss%3Amem%3Ae674cf026df847cbc8da26f02260ad0c"
        class="webkit-html-external-link"
title="https://idp.stanford.edu/idp/profile/SAML2/Redirect/SSO?SAMLRequest=hZLNbsIwEIRfJfKdOBhowSKRUjgUiRZEaA%2B9VE68AUuOnXqd%2Frx9A6EtXOjVnv1mZ7RTFJWuedr4vdnAWwPog89KG%2BTHj5g0znArUCE3ogLkvuBZ%2BrDkLIx47ay3hdUkSBHBeWXNzBpsKnAZuHdVwNNmGZO99zVySneY9wprPBgfohemtE6GIBua7VWeWw1%2BHyJaeuAzul5lWxLM24WUEQf0H0jJ%2BhLQPtB2mVJpOE1vQCoHhadZtiLBYh6TVzES8lbmw9GgLEsW5QDsBkZSjpkcDFk5aWWIDSzMAe1jwqL%2BsBdNetFgyxjvMx6NX0iwPmW%2BU0Yqs7teUN6JkN9vt%2Btel%2BgZHB7TtAKSTA8186OxOyv%2BOlb8tE2Sf7vF326n9MyrM675YwtfzNdWq%2BIrSLW2HzMHwkNM%2BoQm3cjleSTf&amp;RelayState=ss%3Amem%3Ae674cf026df847cbc8da26f02260ad0c"
        target="_blank" style="box-sizing: border-box; color: rgb(84,
        84, 84); text-decoration: none; cursor: pointer;">https://idp.server.com/idp/profile/SAML2/Redirect/SSO?SAMLRequest=hZLNbsI&#8230;HwkNM%2BoQm3cjleSTf&amp;RelayState=ss%3Amem%3Ae674cf026df847cbc8da26f02260ad0c</a>.
      No 'Access-Control-Allow-Origin' header is present on the
      requested resource. Origin '<a
        href="https://gsb-content.stanford.edu/"
        class="webkit-html-external-link"
        title="https://gsb-content.stanford.edu" target="_blank"
        style="box-sizing: border-box; color: rgb(84, 84, 84);
        text-decoration: none; cursor: pointer;">https://server.domain.com</a>'
      is therefore not allowed access.</span><span style="color:
      rgb(255, 0, 0); font-family: Consolas, 'Lucida Console',
      monospace; font-size: 12px; font-style: normal; font-variant:
      normal; font-weight: normal; letter-spacing: normal; line-height:
      normal; orphans: auto; text-align: start; text-indent: 0px;
      text-transform: none; white-space: pre-wrap; widows: auto;
      word-spacing: 0px; -webkit-text-stroke-width: 0px; display: inline
      !important; float: none; background-color: rgb(255, 255, 255);"> </span><br>
    <br>
    The above error causes all kinds of errors in the browser since it
    is usually a JavaScript file that needs to be present for the rest
    of the page to function correctly.<br>
    <br>
    During testing I have set my session lifetime to 60 and timeout to
    30. When I raised this up to the defaults (28800 and 3600
    respectively), I was still seeing errors more frequently than every
    hour.<br>
    <br>
    1. Will raising the lifetime and/or timeout help to solve the
    problem?<br>
    2. Is the session timeout/removal really the cause of my problem?<br>
    3. Is there any obvious error, debugging, or configuration that I
    should look at to troubleshoot this issue?<br>
    <br>
    Many thanks!<br>
    <div class="moz-signature">-- <br>
      Michael <br>
    </div>
  </body>
</html>