<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40"><head><meta http-equiv=Content-Type content="text/html; charset=utf-8"><meta name=Generator content="Microsoft Word 12 (filtered medium)"><!--[if !mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]--><style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
{font-family:Tahoma;
panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:12.0pt;
font-family:"Times New Roman","serif";}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:blue;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:purple;
text-decoration:underline;}
p.MsoAcetate, li.MsoAcetate, div.MsoAcetate
{mso-style-priority:99;
mso-style-link:"Balloon Text Char";
margin:0in;
margin-bottom:.0001pt;
font-size:8.0pt;
font-family:"Tahoma","sans-serif";}
p.emailquote, li.emailquote, div.emailquote
{mso-style-name:emailquote;
mso-margin-top-alt:auto;
margin-right:0in;
mso-margin-bottom-alt:auto;
margin-left:1.0pt;
border:none;
padding:0in;
font-size:12.0pt;
font-family:"Times New Roman","serif";}
span.EmailStyle18
{mso-style-type:personal-reply;
font-family:"Calibri","sans-serif";
color:#1F497D;}
span.BalloonTextChar
{mso-style-name:"Balloon Text Char";
mso-style-priority:99;
mso-style-link:"Balloon Text";
font-family:"Tahoma","sans-serif";}
.MsoChpDefault
{mso-style-type:export-only;
font-size:10.0pt;}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]--></head><body lang=EN-US link=blue vlink=purple><div class=WordSection1><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'>Solved.<o:p></o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'><o:p> </o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'>The stick at the load balance layer was being set to the application’s jsession. Since we don’t require stick as the backend handles the session management, I didn’t realize that there was nothing in the cookie at the beginning as the application only sets the jsession on login. When there was only one path, it worked, but hardly worked when more than one member was behind the balancer. The balancer was reconfigured to stick based on it’s own balance routes instead of the application jsession and now the clustered SPs are talking to testshib just fine and forwarding users into the application.<o:p></o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'><o:p> </o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'>Thanks again Scott for all your help.<o:p></o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'><o:p> </o:p></span></p><div><div class=MsoNormal align=center style='text-align:center'><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'><hr size=2 width="100%" align=center></span></div><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'><o:p> </o:p></span></p><p class=MsoNormal><b><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'>William T. Musil</span></b><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'><o:p></o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'>Manager, Technical Services<o:p></o:p></span></p><p class=MsoNormal style='text-autospace:none'><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'><br></span><b><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";color:#006AA7'>LABVANTAGE</span></b><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'> </span><b><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";color:#999999'>Solutions, Inc.</span></b><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'><o:p></o:p></span></p><p class=MsoNormal style='text-autospace:none'><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'>265 Davidson Avenue, Suite 220<br>Somerset, NJ 08873-4120 USA<br><br>Phone: 908-333-0111<o:p></o:p></span></p><p class=MsoNormal style='margin-bottom:12.0pt;text-autospace:none'><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'>Mobile: 908-531-0835<br>Fax: </span><span lang=EN style='font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'>732-560-0121</span><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'><br>Email: <a href="mailto:wmusil@labvantage.com?subject=Link%20from%20Signature"><span style='color:#1F497D'>wmusil@labvantage.com</span></a><br>Website: <a href="http://www.labvantage.com"><span style='color:#1F497D'>www.labvantage.com</span></a><br>Skype: <a href="skype:bmusil.lvs?chat"><span style='color:#1F497D'>bmusil.lvs</span></a><o:p></o:p></span></p></div><p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'><o:p> </o:p></span></p><div><div style='border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in'><p class=MsoNormal><b><span style='font-size:10.0pt;font-family:"Tahoma","sans-serif"'>From:</span></b><span style='font-size:10.0pt;font-family:"Tahoma","sans-serif"'> users [mailto:users-bounces@shibboleth.net] <b>On Behalf Of </b>Musil, William<br><b>Sent:</b> Sunday, May 31, 2015 4:47 PM<br><b>To:</b> Cantor, Scott; Shib Users<br><b>Subject:</b> RE: multiple sp hosts behind a firewall/proxy etc<o:p></o:p></span></p></div></div><p class=MsoNormal><o:p> </o:p></p><div><p class=MsoNormal>Ok thanks. <o:p></o:p></p></div><div><p class=MsoNormal><o:p> </o:p></p></div><div><p class=MsoNormal>Now that I have a short term way to make it appear to work as it should, while allowing end users to do application funtional testing with the jboss cluster active, I can setup captures along the path, then activate the additional nodes temporarily for the captures, get the data, and then idle the redundant shibd and httpd till I work out what is wrong. <o:p></o:p></p></div><div><p class=MsoNormal><o:p> </o:p></p></div><div><p class=MsoNormal>I'll give that a shot.<o:p></o:p></p></div><div><p class=MsoNormal><o:p> </o:p></p></div><div id="composer_signature"><div><p class=MsoNormal><span style='font-size:10.0pt;color:#575757'>Sent from my Verizon Wireless 4G LTE smartphone<o:p></o:p></span></p></div></div><p class=MsoNormal style='margin-bottom:12.0pt'><br><br>-------- Original message --------<br>From: "Cantor, Scott" <<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>> <br>Date: 05/31/2015 14:03 (GMT-05:00) <br>To: "Musil, William" <<a href="mailto:wmusil@labvantage.com">wmusil@labvantage.com</a>>, Shib Users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>> <br>Subject: Re: multiple sp hosts behind a firewall/proxy etc <o:p></o:p></p><div><p class=MsoNormal style='margin-bottom:12.0pt'><span style='font-size:10.0pt'>On 5/30/15, 11:03 PM, "Musil, William" <<a href="mailto:wmusil@labvantage.com">wmusil@labvantage.com</a>> wrote:<br>><br>>Any ideas from anyone are welcome.<br><br>You need to check all the logs to determine if the cookie is being sent but not accepted, and run traces to see if the cookie's just not being sent.<br><br>There's no way from outside a system to determine the cause of a loop.<br><br>If it's sporadic, then that means the configuration itself is probably intrinsically ok, but that you have a per-transaction influence. Off-hand that leaves a lack of stickiness, which you claim isn't the case, or IP addresses changing and invalidating sessions, which would be logged.<br><br>-- Scott<o:p></o:p></span></p></div></div></body></html>