<html><head><meta http-equiv="Content-Type" content="text/html; charset=utf-8"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class=""><div>Dear Shibboleth Gurus,<br class="">We are experiencing a transient problem that causes a fairly gross error to show up for people during login.<br class="">An example of the error message shown to the user is attached below, but the upshot seems to be this message:<br class="">"You can only resume paused view states, and state {…details...} is not a view state - programmer error” <br class=""><span style="caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);" class="">So far, we cannot easily reproduce this error, and are somewhat baffled by its cause(s).</span><br style="caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);" class="">The error has been occurring for quite a while.  We were previously running Shibboleth IdP v3.4.6, but upgraded to 4.1.6 several months ago.  The error is still occurring on v4.1.6.<br class="">The problem does not happen with great regularity, and people whom it affects are able to log in again right afterwards with no problem.<br class="">The error occurs most frequently (and perhaps exclusively) on our production IdP cluster.  We have four production nodes in the cluster, load balanced by an F5 (with sticky sessions).<br class="">I am attaching some logging (pastebin) from the most recent occurrence of the error that we know of.<br class="">Can you folks help point us in the right direction for tracking down this problem?  99.9% of SSO requests seem to be fine... but the people who encounter this error are likely to start a help desk ticket when they see this, and we’d like to shut down this problem if at all possible.<br class="">I can provide more details about our configuration as needed.<br class="">Thanks,<br class="">Chris Koeritz<br class=""><font color="#ff9f0a" class=""><span style="caret-color: rgb(255, 159, 10);" class=""><br class=""></span></font>idp-process.log with the activity for the user around the time of the error:<br class=""><a href="https://pastebin.com/QS3S28V3" class="">https://pastebin.com/QS3S28V3</a><br class=""><font color="#ff9f0a" class=""><span style="caret-color: rgb(255, 159, 10);" class=""><br class=""></span></font>jetty access.log with activity from the same time frame:<br class=""><a href="https://pastebin.com/AyZKYsd8" class="">https://pastebin.com/AyZKYsd8</a><br class=""><font color="#ff9f0a" class=""><span style="caret-color: rgb(255, 159, 10);" class=""><br class=""></span></font>the visible error message:</div><div><span style="caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);" class="">(Note: Netbadge is just the University of Virginia’s branded SSO, but it is Shibboleth IdP implementing the SSO.)</span><br style="caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);" class=""></div><div><span style="caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0);" class=""><br class=""></span></div><div>Netbadge Message</div><div>Uncaught Exception</div><div><br class=""></div><span class="">A software error was encountered that prevents normal operation:<br class="">java.lang.RuntimeException: java.lang.IllegalStateException: You can only resume paused view states, and state [EndState@39535c9b id = 'ErrorView', flow = 'SAML2/Redirect/SSO', entryActionList = list[[AnnotatedAction@4806b626 targetAction = [EvaluateAction@726f85c9 expression = environment, resultExpression = requestScope.environment], attributes = map[[empty]]], [AnnotatedAction@42886a17 targetAction = [EvaluateAction@619c5159 expression = opensamlProfileRequestContext, resultExpression = requestScope.profileRequestContext], attributes = map[[empty]]], [AnnotatedAction@1cd67cca targetAction = [EvaluateAction@1299f354 expression = T(net.shibboleth.utilities.java.support.codec.HTMLEncoder), resultExpression = requestScope.encoder], attributes = map[[empty]]], [AnnotatedAction@1340fbc2 targetAction = [EvaluateAction@1055766a expression = flowRequestContext.getExternalContext().getNativeRequest(), resultExpression = requestScope.request], attributes = map[[empty]]], [AnnotatedAction@3fca6886 targetAction = [EvaluateAction@62142f78 expression = flowRequestContext.getExternalContext().getNativeResponse(), resultExpression = requestScope.response], attributes = map[[empty]]], [AnnotatedAction@769e5613 targetAction = [EvaluateAction@4dc3988c expression = flowRequestContext.getActiveFlow().getApplicationContext().containsBean('shibboleth.CustomViewContext') ? flowRequestContext.getActiveFlow().getApplicationContext().getBean('shibboleth.CustomViewContext') : null, resultExpression = requestScope.custom], attributes = map[[empty]]]], exceptionHandlerSet = list[net.shibboleth.idp.profile.impl.RethrowingFlowExecutionExceptionHandler@53e2d181], finalResponseAction = org.springframework.webflow.action.ViewFactoryActionAdapter@58011f46, outputMapper = [null]] is not a view state - programmer error</span><div class=""><span class=""><br class="">Please report this problem to your Help Desk or administrative staff. It has also been logged for an administrator to review.<br class=""><br class=""></span><div>-- <br class="">Chris Koeritz<br class="">Senior Linux and Storage Engineer <br class="">University of Virginia ITS - Backup, Storage, and Archive Services<br class="">P: 434 982 4690</div></div></body></html>