<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div id="appendonsend"></div>
<div style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<hr style="display: inline-block; width: 98%;">
<div id="divRplyFwdMsg" dir="ltr"><span style="font-family: Calibri, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);"><b>From:</b> Cantor, Scott <cantor.2@osu.edu><br>
<b>Sent:</b> Tuesday, December 10, 2024 16:39<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Cc:</b> Tomas Liljebergh <Tomas.Liljebergh@oru.se><br>
<b>Subject:</b> Re: Problems with OIDC authentication response must contain a state parameter when using oidc-rp-plugin for shibboleth.</span>
<div> </div>
</div>
<div class="elementToProof" style="font-size: 11pt;">> Everything works fine except for sometimes, when many<br>
> students are logging in at the same time to the same SP.<br>
<br>
That sounds like a race condition, but it's too early to assume where.<br>
<br>
> Users also get the message about "Web Login Service - Stale<br>
> Request" on the login page and never get a chance to log in.<br>
<br>
That goes hand in hand if there's actually no state token, the token value is how the IdP recovers the right conversation to resume after it comes back from the OP.<br>
<br>
Yes, so far we do understand that the state parameter is used to identify the ongoing session.<br>
> Does anyone have any hint on where to look for further error<br>
> investigation.<br>
<br>
You should be at minimum determining if the responses do in fact have a state token or not from web logs.<br>
<br>
We are trying to record a session when this happens, problem is that it only occurs under certain conditions and when it does it is necessary to get this working again so time for problem solving is short.</div>
<div class="elementToProof" style="font-size: 11pt;"><br>
</div>
<div class="elementToProof" style="font-size: 11pt; color: rgb(0, 0, 0);">As far as we know the only thing resolving this is to restart the server running shibboleth.</div>
<div class="elementToProof" style="font-size: 11pt;"><br>
</div>
<div class="elementToProof" style="font-size: 11pt;">We have tried to restart apache, tomcat, passport on the gluu-server and nothing seems to resolve the problem.</div>
<div class="elementToProof" style="font-size: 11pt;"><br>
</div>
<div class="elementToProof" style="font-size: 11pt;">Any ideas are welcome!</div>
<div class="elementToProof" style="font-size: 11pt;"><br>
</div>
<div class="elementToProof" style="font-size: 11pt;">Regards Tomas <br>
<br>
<br>
</div>
</body>
</html>