<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body>
<div>I'll do my best. The link for the SP was like this originally:</div>
<div><br>
</div>
<div><a href="https://jmu-abroad.terradotta.com/secure/">https://jmu.vendor.com/secure</a></div>
<div><br>
</div>
<div>After change, it looked like this:</div>
<div><br>
</div>
<div><a href="https://jmu.vendor.com/secure/">https://jmu.vendor.com/secure/</a></div>
<div><br>
</div>
<div><br>
</div>
<div>As far as I'm aware, it had been like that for a while with Shibboleth 2 in use. Switching to Shibboleth 3 on our end, as far as we can tell, made it start producing double login issues.</div>
<div><br>
</div>
<div>I'm not sure what else may have changed on their end, but that's all they said they had changed. They suspect it's a new change in Shibboleth 3, but I find myself doubtful on that front.</div>
<div><br>
</div>
<div>Hope this makes sense, but let me know.</div>
<div><br>
</div>
<div><br class="Apple-interchange-newline">
<span style="font-family: monospace; white-space: pre;">-- Brandon McKean IT / Systems Linux Administrator (540)568-4235</span></div>
<div><br>
</div>
<div><br>
</div>
<div>On Fri, 2015-08-14 at 14:21 +0000, Cantor, Scott wrote:</div>
<blockquote type="cite">
<pre>On 8/14/15, 9:56 AM, "users on behalf of McKean, Brandon Scott - mckeanbs" <<a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a> on behalf of <a href="mailto:mckeanbs@jmu.edu">mckeanbs@jmu.edu</a>> wrote:
<blockquote type="cite">
Following up on this, we're finding that adding an additional slash, /, to the initial login link that users use to start a session from the SP alleviated the issue here.
</blockquote>
Can you be more specific? I'm not sure I can translate that into what actually was happening, but it sounds as though they might have had differing applicationIds being applied to the resources possibly, and it was crossing an SP application boundary.
-- Scott
</pre>
</blockquote>
</body>
</html>