<div dir="ltr"><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div text="#000000" bgcolor="#FFFFFF">However, when I go back to the same page that I got into, it sends
me back to authenticate again and I see:<br><br>
2016-02-02 11:14:44,670 - DEBUG
[net.shibboleth.idp.cas.flow.impl.ValidateTicket Action:92] -
Attempting to validate ST-1454440484132NQj5toJoKOBk3ZSRFlAd3cQxm<br></div></blockquote><div>... </div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div text="#000000" bgcolor="#FFFFFF">
2016-02-02 11:14:44,671 - INFO
[net.shibboleth.idp.cas.flow.impl.ValidateTicketAction:117] -
Successfully validated ST-1454440484132-NQj5toJoKOBk3ZSRFlAd3cQxm
for <a href="https://ldap-cgi2.dev.sonoma.edu/portal/index.cgi" target="_blank">https://ldap-cgi2.dev.sonoma.edu/portal/index.cgi</a></div></blockquote><div><br></div><div>At this point the CAS protocol work is effectively done and a successful service validation response ought to be returned to your application that allows you access.</div><div><br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div text="#000000" bgcolor="#FFFFFF">
2016-02-02 11:14:45,212 - INFO [Shibboleth-Audit.SSO:241] -
20160202T191445Z||3bc14bcbe2cddd2a5d11079ec2cb352c0fd774e2f5e46729bbf03ba0faef7af0|<a href="https://ldap-cgi2.dev.sonoma.edu/portal/index.cgi" target="_blank">https://ldap-cgi2.dev.sonoma.edu/portal/index.cgi</a>|<a href="https://www.apereo.org/cas/protocol/serviceValidate" target="_blank">https://www.apereo.org/cas/protocol/serviceValidate</a>||||biggsb|||biggsb|ST-1454440484132-NQj5toJoKOBk3ZSRFlAd3cQxm|<br></div></blockquote><div><br></div><div>Further evidence that all is well from the perspective of the IdP.</div><div><br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div text="#000000" bgcolor="#FFFFFF">
(BTW, it's a bit weird seeing
<a href="https://www.apereo.org/cas/protocol/serviceValidate" target="_blank">"https://www.apereo.org/cas/protocol/serviceValidate"</a> in the logs
since i have no references to it...)<br></div></blockquote><div><br></div><div>That's just a protocol URI. It's not a URL to anything anywhere.</div><div><br></div><div>At this point you ought to look more closely at your target application's logs. It sounds like it's (a) not establishing an application session and (b) may be configured for forced authentication (renew=true), which would cause you to log in regardless of an existing IdP session.</div><div><br></div><div>M</div><div><br></div></div></div>