<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">
<div class="">We're using Shibboleth IDP inside Tomcat sat behind Apache (with</div>
<div class="">mod_auth_mellon to do internal SSO) to authenticate users to Office365.</div>
<div class=""><br class="">
</div>
<div class="">Generally this works fine! :-)</div>
<div class=""><br class="">
</div>
<div class="">When the user is finished in Office365 they click Sign Out, their Office365</div>
<div class="">session is destroyed and they're sent off to our local SSO SLO service (which</div>
<div class="">then handles signing them out of anythign else, including the Apache in front</div>
<div class="">of the IDP).</div>
<div class=""><br class="">
</div>
<div class="">Suppose the following:</div>
<div class=""><br class="">
</div>
<div class="">1) User A browses to SP to initiate a logon</div>
<div class="">2) User A hits the Shibboleth IDP's webserver, has no SSO session and is sent away to log in</div>
<div class="">3) User A logs in to SSO and returns to Shibboleth</div>
<div class="">4) User A hits Shibboleth IDP webserver again and request is proxied to Tomcat with REMOTE_USER set</div>
<div class="">5) User A is sent off to SP to check their email and is happy</div>
<div class=""><br class="">
</div>
<div class="">When they're done, User A logs out &amp; SLO reports success! Everything is as it should be.</div>
<div class=""><br class="">
</div>
<div class="">User B then starts the whole process again within the same browser... if this</div>
<div class="">happens in a shortish space of time then User B's SAML2 assertion generated by</div>
<div class="">the Shibboleth IDP for the SP is generated with User A's already resolved</div>
<div class="">attributes.</div>
<div class=""><br class="">
</div>
<div class="">Logs below.</div>
<div class=""><br class="">
</div>
<div class=""><font face="Consolas" class="">&nbsp; &nbsp; &nbsp; &nbsp;1</font></div>
<div class=""><font face="Consolas" class="">&nbsp; &#43;-----------&#43;</font></div>
<div class=""><font face="Consolas" class="">&nbsp; v &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; |</font></div>
<div class=""><font face="Consolas" class="">&#43;----&#43; &nbsp;5 &nbsp; &#43;-------------------&#43; &nbsp;3 &nbsp; &#43;-----&#43;</font></div>
<div class=""><font face="Consolas" class="">| SP | &lt;--- | &nbsp; &nbsp; &nbsp;browser &nbsp; &nbsp; &nbsp;| ---&gt; | SSO |</font></div>
<div class=""><font face="Consolas" class="">&#43;----&#43; &nbsp; &nbsp; &nbsp;&#43;-------------------&#43; &nbsp; &nbsp; &nbsp;&#43;-----&#43;</font></div>
<div class=""><font face="Consolas" class="">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; | &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;|</font></div>
<div class=""><font face="Consolas" class="">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; | 4 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;| 2</font></div>
<div class=""><font face="Consolas" class="">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; v &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;|</font></div>
<div class=""><font face="Consolas" class="">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &#43;-------------&#43; &nbsp;|</font></div>
<div class=""><font face="Consolas" class="">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; | httpd&#43;authz | &lt;&#43;</font></div>
<div class=""><font face="Consolas" class="">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &#43;-------------&#43;</font></div>
<div class=""><font face="Consolas" class="">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; |</font></div>
<div class=""><font face="Consolas" class="">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; | 4A</font></div>
<div class=""><font face="Consolas" class="">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; v</font></div>
<div class=""><font face="Consolas" class="">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &#43;-------------&#43;</font></div>
<div class=""><font face="Consolas" class="">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; | &nbsp; &nbsp; idp &nbsp; &nbsp; |</font></div>
<div class=""><font face="Consolas" class="">&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &#43;-------------&#43;</font></div>
<div class=""><br class="">
</div>
<div class="">I tried disabling the PreviousSession Login Handler (<a href="https://wiki.shibboleth.net/confluence/display/SHIB2/IdPAuthPreviousSession" class="">https://wiki.shibboleth.net/confluence/display/SHIB2/IdPAuthPreviousSession</a>) to no avail.</div>
<div class=""><br class="">
</div>
<div class="">I have verified that the REMOTE_USER going over AJP is correctly changing between User A and User B.</div>
<div class=""><br class="">
</div>
<div class="">Any other ideas?</div>
<div class=""><br class="">
</div>
<div class="">Thankyou!</div>
<div class="">foo</div>
<div class=""><br class="">
</div>
<div class=""><br class="">
</div>
<div class="">=== LOGS (Apache and IDP interleaved) ===</div>
<div class=""><br class="">
</div>
<div class="">User A logging in</div>
<div class="">-----------------</div>
<div class=""><br class="">
</div>
<div class="">1.2.3.4 - - [12/Mar/2015:10:53:00 &#43;0000] &quot;GET /r/ HTTP/1.1&quot; 303 415</div>
<div class="">1.2.3.4 - - [12/Mar/2015:10:53:00 &#43;0000] &quot;GET /mellon/login?ReturnTo=https%3A%2F%<a href="http://2Fdan.kent.ac.uk" class="">2Fdan.kent.ac.uk</a>%2Fr%2F&amp;IdP=https%3A%2F%<a href="http://2Fsso.id.kent.ac.uk" class="">2Fsso.id.kent.ac.uk</a>%2Fidp
 HTTP/1.1&quot; 303 1354</div>
<div class="">1.2.3.4 - - [12/Mar/2015:10:53:06 &#43;0000] &quot;POST /mellon/postResponse HTTP/1.1&quot; 303 314</div>
<div class="">1.2.3.4 - user_a [12/Mar/2015:10:53:06 &#43;0000] &quot;GET /r/ HTTP/1.1&quot; 302 301</div>
<div class="">1.2.3.4 - user_a [12/Mar/2015:10:53:07 &#43;0000] &quot;POST /idp-b/profile/SAML2/POST/SSO HTTP/1.1&quot; 302 -</div>
<div class="">1.2.3.4 - user_a [12/Mar/2015:10:53:07 &#43;0000] &quot;GET /idp-b/AuthnEngine HTTP/1.1&quot; 302 -</div>
<div class="">1.2.3.4 - user_a [12/Mar/2015:10:53:07 &#43;0000] &quot;GET /idp-b/Authn/RemoteUser HTTP/1.1&quot; 302 -</div>
<div class="">20150312T105308Z|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST|_7157c1e3-f97a-445e-b475-09b71f37e68e|urn:federation:MicrosoftOnline|urn:mace:shibboleth:2.0:profiles:saml2:sso|<a href="https://dan.kent.ac.uk/idp-b/shibboleth|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST|_47824311b39c0156fc1fb87fd035b4f7|user_a|urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport|transientId,UserId,ImmutableID,|tcZvZyqWA0ewAPx4bIxz9g==|_f3863de26771d6dadc81c40f402cfbc0,|" class="">https://dan.kent.ac.uk/idp-b/shibboleth|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST|_47824311b39c0156fc1fb87fd035b4f7|user_a|urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport|transientId,UserId,ImmutableID,|tcZvZyqWA0ewAPx4bIxz9g==|_f3863de26771d6dadc81c40f402cfbc0,|</a></div>
<div class="">1.2.3.4 - user_a [12/Mar/2015:10:53:07 &#43;0000] &quot;GET /idp-b/profile/SAML2/POST/SSO HTTP/1.1&quot; 200 7840</div>
<div class="">1.2.3.4 - - [12/Mar/2015:10:53:28 &#43;0000] &quot;GET /mellon/logout?SAMLRequest=&lt;removed&gt; HTTP/1.1&quot; 303 1255</div>
<div class=""><br class="">
</div>
<div class="">User B logging in</div>
<div class="">-----------------</div>
<div class=""><br class="">
</div>
<div class="">1.2.3.4 - - [12/Mar/2015:10:53:31 &#43;0000] &quot;GET /r/ HTTP/1.1&quot; 303 415</div>
<div class="">1.2.3.4 - - [12/Mar/2015:10:53:31 &#43;0000] &quot;GET /mellon/login?ReturnTo=https%3A%2F%<a href="http://2Fdan.kent.ac.uk" class="">2Fdan.kent.ac.uk</a>%2Fr%2F&amp;IdP=https%3A%2F%<a href="http://2Fsso.id.kent.ac.uk" class="">2Fsso.id.kent.ac.uk</a>%2Fidp
 HTTP/1.1&quot; 303 1346</div>
<div class="">1.2.3.4 - - [12/Mar/2015:10:53:33 &#43;0000] &quot;POST /mellon/postResponse HTTP/1.1&quot; 303 314</div>
<div class="">1.2.3.4 - user_b [12/Mar/2015:10:53:33 &#43;0000] &quot;GET /r/ HTTP/1.1&quot; 302 301</div>
<div class="">1.2.3.4 - user_b [12/Mar/2015:10:53:34 &#43;0000] &quot;POST /idp-b/profile/SAML2/POST/SSO HTTP/1.1&quot; 302 -</div>
<div class="">1.2.3.4 - user_b [12/Mar/2015:10:53:34 &#43;0000] &quot;GET /idp-b/AuthnEngine HTTP/1.1&quot; 302 -</div>
<div class="">1.2.3.4 - user_b [12/Mar/2015:10:53:34 &#43;0000] &quot;GET /idp-b/Authn/RemoteUser HTTP/1.1&quot; 302 -</div>
<div class="">20150312T105334Z|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST|_afc5a5eb-ab77-44b7-8b7a-e245ea3df925|urn:federation:MicrosoftOnline|urn:mace:shibboleth:2.0:profiles:saml2:sso|<a href="https://dan.kent.ac.uk/idp-b/shibboleth|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST|_1ade3c708ffb70646fa4bb580608f32f|user_a|urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport|transientId,UserId,ImmutableID,|tcZvZyqWA0ewAPx4bIxz9g==|_959cdc3f5ecd22e17a7f5effd5e8be1f,|" class="">https://dan.kent.ac.uk/idp-b/shibboleth|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST|_1ade3c708ffb70646fa4bb580608f32f|user_a|urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport|transientId,UserId,ImmutableID,|tcZvZyqWA0ewAPx4bIxz9g==|_959cdc3f5ecd22e17a7f5effd5e8be1f,|</a></div>
<div class="">1.2.3.4 - user_b [12/Mar/2015:10:53:34 &#43;0000] &quot;GET /idp-b/profile/SAML2/POST/SSO HTTP/1.1&quot; 200 7830</div>
<div class=""><br class="">
</div>
<div class="">Note how in the IDP audit log line it is user_a being returned...</div>
<div apple-content-edited="true" class="">
<div style="color: rgb(0, 0, 0); letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">
<div class=""><br class="">
</div>
<div class=""><br class="">
</div>
<div class=""><br class="">
</div>
<div class="">--&nbsp;</div>
<div class=""><b class="">Matthew Slowe<span class="Apple-converted-space">&nbsp;</span></b>| Server Infrastructure Officer</div>
<div class="">IT Infrastructure, Information Services, University of Kent</div>
<div class="">Room S21, Cornwallis South</div>
<div class="">Canterbury, Kent, CT2 7NZ, UK</div>
<div class="">Tel: &#43;44 (0)1227 824265</div>
<div class=""><br class="">
</div>
<div class=""><a href="http://www.kent.ac.uk/is" class="">www.kent.ac.uk/is</a> | @UnikentUnseenIT | @UKCLibraryIt</div>
</div>
</div>
<br class="">
</body>
</html>