<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Exchange Server">
<!-- converted from text --><style><!-- .EmailQuote { margin-left: 1pt; padding-left: 4pt; border-left: #800000 2px solid; } --></style>
</head>
<body>
<meta content="text/html; charset=UTF-8">
<style type="text/css" style="">
<!--
p
        {margin-top:0;
        margin-bottom:0}
-->
</style>
<div dir="ltr">
<div id="x_divtagdefaultwrapper" dir="ltr" style="font-size:12pt; color:#000000; font-family:Calibri,Arial,Helvetica,sans-serif">
<p>> <span style="color:rgb(33,33,33); font-size:13.3333px">Right, so they're literally failing logging in, as opposed to a back button thing.</span></p>
<p><span style="color:rgb(33,33,33); font-size:13.3333px"><br>
</span></p>
<p><span style="color:rgb(33,33,33); font-size:13.3333px">They're getting stopped at the IdP and I can associate that with replays and expirations by identifying authenticated users in the web server's logs and response sizes(this being the ugly aspect of our
 current implementation).  It's totally plausible that something environment-specific is involved here, particularly given the network already being implicated.</span></p>
<p><span style="color:rgb(33,33,33); font-size:13.3333px"><br>
</span></p>
<p><span style="color:rgb(33,33,33); font-size:13.3333px">> <span style="color:rgb(33,33,33); font-size:13.3333px">But...I also don't think that will fix it. Pretty sure webflow will just break anyway, but it would depend on exactly what's going on.</span></span></p>
<p><span style="color:rgb(33,33,33); font-size:13.3333px"><span style="color:rgb(33,33,33); font-size:13.3333px"><br>
</span></span></p>
<p><span style="color:rgb(33,33,33); font-size:13.3333px"><span style="color:rgb(33,33,33); font-size:13.3333px">That was my hunch based on prior responses and conversations.  This is much more at the "try it and see what happens" phase than anywhere else.
  I already understand that I barely understand Webflow.</span></span></p>
<p><span style="color:rgb(33,33,33); font-size:13.3333px"><span style="color:rgb(33,33,33); font-size:13.3333px"><br>
</span></span></p>
<p><span style="color:rgb(33,33,33); font-size:13.3333px"><span style="color:rgb(33,33,33); font-size:13.3333px">I'll see if I can reasonably test something, realizing full well that this is likely to result in incidental unexpected behavior by Webflow that
 would otherwise get trapped and caught.</span></span></p>
<p><span style="color:rgb(33,33,33); font-size:13.3333px"><span style="color:rgb(33,33,33); font-size:13.3333px"><br>
</span></span></p>
<p><span style="color:rgb(33,33,33); font-size:13.3333px"><span style="color:rgb(33,33,33); font-size:13.3333px">At most I would ask for a flag like idp.encryption.optional, so if Webflow doesn't careen off the rails, I'll file an RFE for a boolean and a prayer.
  This isn't a top priority when I can't reliably reproduce it myself.</span></span></p>
</div>
<hr tabindex="-1" style="display:inline-block; width:98%">
<div id="x_divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" color="#000000" style="font-size:11pt"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Cantor, Scott <cantor.2@osu.edu><br>
<b>Sent:</b> Wednesday, April 19, 2017 4:08:27 PM<br>
<b>To:</b> Shib Users<br>
<b>Subject:</b> Re: "Replay detected of message" causes</font>
<div> </div>
</div>
</div>
<font size="2"><span style="font-size:10pt;">
<div class="PlainText">On 4/19/17, 7:00 PM, "users on behalf of Nate Klingenstein" <users-bounces@shibboleth.net on behalf of ndk@sudonym.me> wrote:<br>
<br>
> It is squelched right now, but we hear the complaints from users, and<br>
> they're much harder to squelch.<br>
<br>
I can tell you from experience that turning an error page you can entirely control the text on into a fence they can't back up over will not improve the general run of the mill complaints, but I think there are two issues conflated, and now I understand what
 we're talking about.<br>
<br>
The vast majority of these are nothing, but the complaints are coming from, I guess, people on broken systems.<br>
<br>
> We only get complaints from users<br>
> on devices that are not on campus networks, but that's the only common<br>
> factor that I could observe, and I can't reasonably restrict that.<br>
<br>
Right, so they're literally failing logging in, as opposed to a back button thing.<br>
<br>
Well...I don't get these reports so I'm not aware that this is a thing. If it is, then I guess you would need to disable the check, but the only safe way to do that is by crafting a custom flow that omits only those steps or by asking for a RFE to actually
 implement that.<br>
<br>
But...I also don't think that will fix it. Pretty sure webflow will just break anyway, but it would depend on exactly what's going on.<br>
<br>
-- Scott<br>
<br>
<br>
-- <br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font>
</body>
</html>