<html>
<head>
<meta http-equiv="content-type" content="text/html; charset=ISO-8859-1">
</head>
<body bgcolor="#FFFFFF" text="#000000">
I am running Alfresco, an open source web based ECM, behind
Shibboleth (Apache 2). Alfresco has quite a few XML HTTP requests
(AJAX). Occasionally, we can't discern any reason as to when, we are
seeing a page fail to completely load. When this happens it appears
that the session has been dropped on the SP side and the SP fails to
send a SAML POST to the IDP. I have exhausted my (limited) knowledge
on the subject and could really use some help troubleshooting the
issue.<br>
<br>
On failure, the shibd.log on the SP has (identifying information
removed):<br>
2014-09-04 07:46:58 INFO Shibboleth.SessionCache [3]: new session
created: ID (_8afc83602ee907b1e83992c61fef98dd) IdP
(<a class="moz-txt-link-freetext" href="https://idp.domain.com/">https://idp.domain.com/</a>)
Protocol(urn:oasis:names:tc:SAML:2.0:protocol) Address (10.0.135.18)<br>
2014-09-04 07:46:58 DEBUG Shibboleth.SSO.SAML2 [3]: ACS returning
via redirect to: <a class="moz-txt-link-freetext" href="https://server.domain.com/share/page/repository">https://server.domain.com/share/page/repository</a><br>
2014-09-04 07:47:59 INFO Shibboleth.SessionCache [6]: removed
session (_8afc83602ee907b1e83992c61fef98dd)<br>
2014-09-04 07:47:59 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [6]:
validating input<br>
2014-09-04 07:47:59 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [6]:
marshalling, deflating, base64-encoding the message<br>
2014-09-04 07:47:59 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [6]:
marshalled message:<br>
...<cut><br>
2014-09-04 07:47:59 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [6]:
message encoded, sending redirect to client<br>
2014-09-04 07:47:59 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [6]:
validating input<br>
2014-09-04 07:47:59 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [6]:
marshalling, deflating, base64-encoding the message<br>
2014-09-04 07:47:59 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [6]:
marshalled message:<br>
<br>
I notice that a "normal" successful interaction is more like this
(note the SAML2POST):<br>
2014-09-04 11:39:24 INFO Shibboleth.SessionCache [2]: removed
session (_32645b3099cdfa688622954b1ac4a8c9)<br>
2014-09-04 11:39:24 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [2]:
validating input<br>
2014-09-04 11:39:24 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [2]:
marshalling, deflating, base64-encoding the message<br>
2014-09-04 11:39:24 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [2]:
marshalled message:<br>
...<cut><br>
2014-09-04 11:39:24 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [2]:
message encoded, sending redirect to client<br>
2014-09-04 11:39:27 DEBUG OpenSAML.MessageDecoder.SAML2POST [1]:
validating input<br>
2014-09-04 11:39:27 DEBUG OpenSAML.MessageDecoder.SAML2POST [1]:
decoded SAML message:<br>
...<cut><br>
<br>
The failed authentication shows the following on the IdP side:<br>
15:29:32.931 - WARN
[edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler:371]
- Error decoding authentication request message
<br>
org.opensaml.ws.message.decoder.MessageDecodingException: No
SAMLRequest or SAMLResponse query path parameter, invalid SAML 2
HTTP Redirect message
<br>
<br>
The end result is errors like this in the browser:<br>
<span style="box-sizing: border-box; color: rgb(255, 0, 0);
font-family: Consolas, 'Lucida Console', monospace; font-size:
12px; font-style: normal; font-variant: normal; font-weight:
normal; letter-spacing: normal; line-height: normal; orphans:
auto; text-align: start; text-indent: 0px; text-transform: none;
white-space: pre-wrap; widows: auto; word-spacing: 0px;
-webkit-text-stroke-width: 0px; background-color: rgb(255, 255,
255);">XMLHttpRequest cannot load <a
href="https://idp.stanford.edu/idp/profile/SAML2/Redirect/SSO?SAMLRequest=hZLNbsIwEIRfJfKdOBhowSKRUjgUiRZEaA%2B9VE68AUuOnXqd%2Frx9A6EtXOjVnv1mZ7RTFJWuedr4vdnAWwPog89KG%2BTHj5g0znArUCE3ogLkvuBZ%2BrDkLIx47ay3hdUkSBHBeWXNzBpsKnAZuHdVwNNmGZO99zVySneY9wprPBgfohemtE6GIBua7VWeWw1%2BHyJaeuAzul5lWxLM24WUEQf0H0jJ%2BhLQPtB2mVJpOE1vQCoHhadZtiLBYh6TVzES8lbmw9GgLEsW5QDsBkZSjpkcDFk5aWWIDSzMAe1jwqL%2BsBdNetFgyxjvMx6NX0iwPmW%2BU0Yqs7teUN6JkN9vt%2Btel%2BgZHB7TtAKSTA8186OxOyv%2BOlb8tE2Sf7vF326n9MyrM675YwtfzNdWq%2BIrSLW2HzMHwkNM%2BoQm3cjleSTf&RelayState=ss%3Amem%3Ae674cf026df847cbc8da26f02260ad0c"
class="webkit-html-external-link"
title="https://idp.stanford.edu/idp/profile/SAML2/Redirect/SSO?SAMLRequest=hZLNbsIwEIRfJfKdOBhowSKRUjgUiRZEaA%2B9VE68AUuOnXqd%2Frx9A6EtXOjVnv1mZ7RTFJWuedr4vdnAWwPog89KG%2BTHj5g0znArUCE3ogLkvuBZ%2BrDkLIx47ay3hdUkSBHBeWXNzBpsKnAZuHdVwNNmGZO99zVySneY9wprPBgfohemtE6GIBua7VWeWw1%2BHyJaeuAzul5lWxLM24WUEQf0H0jJ%2BhLQPtB2mVJpOE1vQCoHhadZtiLBYh6TVzES8lbmw9GgLEsW5QDsBkZSjpkcDFk5aWWIDSzMAe1jwqL%2BsBdNetFgyxjvMx6NX0iwPmW%2BU0Yqs7teUN6JkN9vt%2Btel%2BgZHB7TtAKSTA8186OxOyv%2BOlb8tE2Sf7vF326n9MyrM675YwtfzNdWq%2BIrSLW2HzMHwkNM%2BoQm3cjleSTf&RelayState=ss%3Amem%3Ae674cf026df847cbc8da26f02260ad0c"
target="_blank" style="box-sizing: border-box; color: rgb(84,
84, 84); text-decoration: none; cursor: pointer;">https://idp.server.com/idp/profile/SAML2/Redirect/SSO?SAMLRequest=hZLNbsI…HwkNM%2BoQm3cjleSTf&RelayState=ss%3Amem%3Ae674cf026df847cbc8da26f02260ad0c</a>.
No 'Access-Control-Allow-Origin' header is present on the
requested resource. Origin '<a
href="https://gsb-content.stanford.edu/"
class="webkit-html-external-link"
title="https://gsb-content.stanford.edu" target="_blank"
style="box-sizing: border-box; color: rgb(84, 84, 84);
text-decoration: none; cursor: pointer;">https://server.domain.com</a>'
is therefore not allowed access.</span><span style="color:
rgb(255, 0, 0); font-family: Consolas, 'Lucida Console',
monospace; font-size: 12px; font-style: normal; font-variant:
normal; font-weight: normal; letter-spacing: normal; line-height:
normal; orphans: auto; text-align: start; text-indent: 0px;
text-transform: none; white-space: pre-wrap; widows: auto;
word-spacing: 0px; -webkit-text-stroke-width: 0px; display: inline
!important; float: none; background-color: rgb(255, 255, 255);"> </span><br>
<br>
The above error causes all kinds of errors in the browser since it
is usually a JavaScript file that needs to be present for the rest
of the page to function correctly.<br>
<br>
During testing I have set my session lifetime to 60 and timeout to
30. When I raised this up to the defaults (28800 and 3600
respectively), I was still seeing errors more frequently than every
hour.<br>
<br>
1. Will raising the lifetime and/or timeout help to solve the
problem?<br>
2. Is the session timeout/removal really the cause of my problem?<br>
3. Is there any obvious error, debugging, or configuration that I
should look at to troubleshoot this issue?<br>
<br>
Many thanks!<br>
<div class="moz-signature">-- <br>
Michael <br>
</div>
</body>
</html>