I get into another user session when logging in openam -
We have deployed an OpenM V10 cluster with two nodes, and sometimes many more SP have been configured. When a user logs into the system, then the system validates its credentials and the user initiates the session, but sometimes the session starts with "cross" from the other user, which is already logged into the system. . After that, when the user tries to access any registered SP, an error is displayed and it is forced to log on again. Therefore, in fact, this is not really a security problem, but it is not quite calm.
We do not really know whether the problem is in OpenM or load-balancer.
Any ideas are welcome.
does not use OpenM HTTP sessions, but it is itself a session ID which is cryptographic safe, It is therefore not very likely that an SSO session ID conflict occurs.
It is not clear what exactly "to cross the session" means ... a session in you app? Then this is an application issue, there is not an OpenM problem.
This will never be the LB score.
Comments
Post a Comment