Hi,
We are multi-tenant application allowing login via multiple IDP. Most of those are Shibboleth IDP and some are using ADFS. Off-late, we see frequent errors in the shibd.log for ADFS providers:
2019-05-04 12:49:53 ERROR OpenSAML.SecurityPolicyRule.MessageFlow [1] [<i>SP URL</i>]: replay detected of message ID (_f3ce22fe-1c01-41c5-9e18-205b77b04b73)
2019-05-04 12:49:53 WARN Shibboleth.SSO.SAML2 [1] [<i>SP URL</i>]: error processing incoming assertion: Rejecting replayed message ID (_f3ce22fe-1c01-41c5-9e18-205b77b04b73).
2019-05-04 12:49:55 ERROR OpenSAML.SecurityPolicyRule.MessageFlow [3] [<i>SP URL</i>]: replay detected of message ID (_f3ce22fe-1c01-41c5-9e18-205b77b04b73)
2019-05-04 12:49:55 WARN Shibboleth.SSO.SAML2 [3] [<i>SP URL</i>]: error processing incoming assertion: Rejecting replayed message ID (_f3ce22fe-1c01-41c5-9e18-205b77b04b73).
For few of the requests, we seen following errors as well:
2019-05-07 13:42:53 WARN Shibboleth.SSO.SAML2 [2] [<i>SP URL</i>]: error processing incoming assertion: SAML response reported an IdP error.
Is there any configuration at SP side that we must be checking to address these issues?
<br/><hr align="left" width="300" />
Sent from the <a href="http://shibboleth.1660669.n2.nabble.com/Shibboleth-Users-f1660767.html">Shibboleth - Users mailing list archive</a> at Nabble.com.<br/>