<div dir="ltr">A newish service inconsistently honors users' existing SSO sessions.<br><br>The initial signin link (in our student portal) issues a request to a service with Issuer and ACS suggesting OAuth:<br><br><span class="gmail-hljs-tag" style="font-family:SFMono-Regular,Menlo,Monaco,Consolas,"Lucida Console","Liberation Mono","Courier New",Courier,monospace;font-size:10.6667px"><<span class="gmail-hljs-name">saml2p:AuthnRequest</span> <span class="gmail-hljs-attr">xmlns:saml2p</span>=<span class="gmail-hljs-string">"urn:oasis:names:tc:SAML:2.0:protocol"</span>            <span class="gmail-hljs-attr">AssertionConsumerServiceURL</span>=<span class="gmail-hljs-string">"https://....oauth....com:443/saml/SSO"</span>
<span class="gmail-hljs-attr">Destination</span>=<span class="gmail-hljs-string">"<a href="https://sso.civitaslearning.com/realms/alaska-prod/protocol/saml">https://sso.civitaslearning.com/realms/alaska-prod/protocol/saml</a>"</span>
                     <span class="gmail-hljs-attr">ForceAuthn</span>=<span class="gmail-hljs-string">"false"...</span>
                     <span class="gmail-hljs-attr">IsPassive</span>=<span class="gmail-hljs-string">"false"</span>
                     <span class="gmail-hljs-attr">IssueInstant</span>=<span class="gmail-hljs-string">"..."</span>
                     <span class="gmail-hljs-attr">ProtocolBinding</span>=<span class="gmail-hljs-string">"urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"</span>
                     <span class="gmail-hljs-attr">Version</span>=<span class="gmail-hljs-string">"2.0"</span>
                     ></span><span style="color:rgb(56,56,61);font-family:SFMono-Regular,Menlo,Monaco,Consolas,"Lucida Console","Liberation Mono","Courier New",Courier,monospace;font-size:10.6667px">
</span><span class="gmail-hljs-tag" style="font-family:SFMono-Regular,Menlo,Monaco,Consolas,"Lucida Console","Liberation Mono","Courier New",Courier,monospace;font-size:10.6667px"><<span class="gmail-hljs-name">saml2:Issuer </span><span class="gmail-hljs-attr">xmlns:saml2</span>=<span class="gmail-hljs-string">"urn:oasis:names:tc:SAML:2.0:assertion"</span>>
</span><span style="color:rgb(56,56,61);font-family:SFMono-Regular,Menlo,Monaco,Consolas,"Lucida Console","Liberation Mono","Courier New",Courier,monospace;font-size:10.6667px">https://....oauth....com:443/saml</span><span class="gmail-hljs-tag" style="font-family:SFMono-Regular,Menlo,Monaco,Consolas,"Lucida Console","Liberation Mono","Courier New",Courier,monospace;font-size:10.6667px"></<span class="gmail-hljs-name">saml2:Issuer</span>></span><span style="color:rgb(56,56,61);font-family:SFMono-Regular,Menlo,Monaco,Consolas,"Lucida Console","Liberation Mono","Courier New",Courier,monospace;font-size:10.6667px">
</span><span class="gmail-hljs-tag" style="font-family:SFMono-Regular,Menlo,Monaco,Consolas,"Lucida Console","Liberation Mono","Courier New",Courier,monospace;font-size:10.6667px"></<span class="gmail-hljs-name">saml2p:AuthnRequest</span>>
</span><span class="gmail-hljs-tag" style="white-space-collapse: preserve;"><font face="arial, sans-serif" style="">
That service in turn sends a request to our institutional SSO (Shibb IdP):
</font></span><span class="gmail-hljs-tag" style="white-space-collapse: preserve;"><font face="SFMono-Regular, Menlo, Monaco, Consolas, Lucida Console, Liberation Mono, Courier New, Courier, monospace" style="font-size:10.6667px">
</font><span class="gmail-hljs-tag" style="font-size:10.6667px;font-family:SFMono-Regular,Menlo,Monaco,Consolas,"Lucida Console","Liberation Mono","Courier New",Courier,monospace"><<span class="gmail-hljs-name">samlp:AuthnRequest</span> <span class="gmail-hljs-attr">xmlns:samlp</span>=<span class="gmail-hljs-string">"urn:oasis:names:tc:SAML:2.0:protocol"</span>
                    <span class="gmail-hljs-attr">xmlns</span>=<span class="gmail-hljs-string">"urn:oasis:names:tc:SAML:2.0:assertion"</span>
                    <span class="gmail-hljs-attr">xmlns:saml</span>=<span class="gmail-hljs-string">"urn:oasis:names:tc:SAML:2.0:assertion"</span>
                    <span class="gmail-hljs-attr">AssertionConsumerServiceURL</span>=<span class="gmail-hljs-string">"<a href="https://sso.">https://sso.</a>.../endpoint"</span>
                    <span class="gmail-hljs-attr">Destination</span>=<span class="gmail-hljs-string">"<a href="https://idp.alaska.edu/idp/profile/SAML2/POST/SSO">https://idp.alaska.edu/idp/profile/SAML2/POST/SSO</a>"</span>
                    <span class="gmail-hljs-attr">ForceAuthn</span>=<span class="gmail-hljs-string">"false"</span>
                    <span class="gmail-hljs-attr">IssueInstant</span>=<span class="gmail-hljs-string">"..."</span>
                    <span class="gmail-hljs-attr">ProtocolBinding</span>=<span class="gmail-hljs-string">"urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"</span>
                    <span class="gmail-hljs-attr">Version</span>=<span class="gmail-hljs-string">"2.0"</span>
                    ></span><span style="font-size:10.6667px;font-family:SFMono-Regular,Menlo,Monaco,Consolas,"Lucida Console","Liberation Mono","Courier New",Courier,monospace;color:rgb(56,56,61)">
</span><span class="gmail-hljs-tag" style="font-size:10.6667px;font-family:SFMono-Regular,Menlo,Monaco,Consolas,"Lucida Console","Liberation Mono","Courier New",Courier,monospace"><<span class="gmail-hljs-name">saml:Issuer</span>></span><span style="font-size:10.6667px;font-family:SFMono-Regular,Menlo,Monaco,Consolas,"Lucida Console","Liberation Mono","Courier New",Courier,monospace;color:rgb(56,56,61)"><a href="https://sso.">https://sso.</a>...</</span><span class="gmail-hljs-tag" style="font-size:10.6667px;font-family:SFMono-Regular,Menlo,Monaco,Consolas,"Lucida Console","Liberation Mono","Courier New",Courier,monospace"><span class="gmail-hljs-name">saml:Issuer</span>></span><span style="font-size:10.6667px;font-family:SFMono-Regular,Menlo,Monaco,Consolas,"Lucida Console","Liberation Mono","Courier New",Courier,monospace;color:rgb(56,56,61)">
</span><span class="gmail-hljs-tag" style=""><font face="SFMono-Regular, Menlo, Monaco, Consolas, Lucida Console, Liberation Mono, Courier New, Courier, monospace" style="font-size:10.6667px"></</font><span class="gmail-hljs-name" style="font-size:10.6667px;font-family:SFMono-Regular,Menlo,Monaco,Consolas,"Lucida Console","Liberation Mono","Courier New",Courier,monospace">samlp:AuthnRequest</span><font face="SFMono-Regular, Menlo, Monaco, Consolas, Lucida Console, Liberation Mono, Courier New, Courier, monospace" style="font-size:10.6667px">>

</font><font face="arial, sans-serif" style="">Users must have created an SSO session to get to that first link inside the student portal, and I've verified SSO to other services without forcing re-authentication.
ForceAuthn is "false" for the two requests as indicated in snippets above. Nevertheless, users generally have to re-authenticate to our institutional IdP for that second service. 
</font><font style="" face="arial, sans-serif">
I wondered if some process involved in that cascade of saml requests destroyed or invalidated the SSO session cookie. But I verified that after the demand for re-authentication, but prior to re-authenticating, other SSO-enabled service all work as expected, relying on the initial SSO session used to sign in to the student portal.

The behavior described is not consistent - generally re-authentication is required in Chrome, but not in Firefox, and sometimes yes, sometimes no in a Chrome incognito window.

Users and administrators rightly object to this behavior and want SSO to be honored. I won't poison the well with my unfounded speculations, instead asking for your constructive ideas on how to track this down. (Yes, we've asked the vendor, who has so far responded with crickets.)
</font><font style=""><font face="SFMono-Regular, Menlo, Monaco, Consolas, Lucida Console, Liberation Mono, Courier New, Courier, monospace" style="font-size:10.6667px">
</font><font face="arial, sans-serif" style="">David St Pierre Bantz</font></font></span></span><div><span class="gmail-hljs-tag" style="white-space-collapse: preserve;"><span class="gmail-hljs-tag" style=""><font style="" face="arial, sans-serif">UA IAM</font></span></span></div></div>