<div dir="ltr"><div class="gmail_quote"><div dir="ltr">On Wed, Aug 2, 2017 at 7:39 AM Rod Widdowson <<a href="mailto:rdw@steadingsoftware.com">rdw@steadingsoftware.com</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Is there anything 'interesting' about your network set up (multiple network adaptors or something such that SAML requests come in<br>
one another adaptor and the CAS another)?<br></blockquote><div><br></div><div>Network effects are the best explanation for the behavior I can imagine. We could confirm or refute that idea by configuring the logger to log the source IP address; if it's different on the SAML request, then we'd have a smoking gun. See <a href="https://wiki.shibboleth.net/confluence/display/IDP30/LoggingConfiguration">https://wiki.shibboleth.net/confluence/display/IDP30/LoggingConfiguration</a> for more information. You probably want to log the source IP anyway; we've found it extremely helpful for correlating log events for both troubleshooting and abuse investigations.</div><div><br></div><div>M<a href="mailto:users-unsubscribe@shibboleth.net" target="_blank"></a><br>
</div><div><br></div></div></div>