<p dir="ltr">Hi ,<br>
I too experienced this behavior . From the logs its evident that IDP 3.1.1 is doing lookup of shibboleth session id and deserialise attributes . </p>
<p dir="ltr">Hence I have few queries</p>
<p dir="ltr">How to prevent idp3.1.1 from caching attributes ?<br>
Or can I change cookie name of shibboleth based on 'idp.domain' domains port dynamically?</p>
<p dir="ltr">Please suggest .....</p>
<div class="gmail_quote">On Oct 1, 2015 7:13 PM, "Cantor, Scott" <<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>> wrote:<br type="attribution"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">On 10/1/15, 8:07 AM, "users on behalf of sarath upadrista" <<a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a> on behalf of <a href="mailto:upadrista.sarath@gmail.com">upadrista.sarath@gmail.com</a>> wrote:<br>
><br>
>At Brower-1 Tab2 ,<br>
>When accessing Instance#2-(<a href="http://localhost:9999/app" rel="noreferrer" target="_blank">http://localhost:9999/app</a>), IdP3.1.1 is signalling this request as already authentic and responding with<br>
>A) Destination="<a href="http://localhost:9999/ConsumerServiceURL/SSO" rel="noreferrer" target="_blank">http://localhost:9999/ConsumerServiceURL/SSO</a>" and<br>
>B) saml2:AttributeStatement containg "username=slp145,accountType=10,sessionId=_f1cd58432436b7ac788fb7356e8a1328"<br>
>Please note here AttributeStatement for At Brower-1 Tab2 is not expected behaviour<br>
<br>
Well, that's up to the resolver configuration. The data connector results from the first login are cached if you tell it to do so, and in general there is no reason why attributes will tend to be different based on the SP unless the definitions make them different.<br>
<br>
>Please suggest Whether IdP 3.1.1 Behavior is correct for the above said scenario<br>
<br>
The only person who could possibly answer that is you.<br>
<br>
-- Scott<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>