Uploaded image for project: 'OpenAM'
  1. OpenAM
  2. OPENAM-11485

Session upgrade is not working in Chrome


    • Type: Bug
    • Status: Open
    • Priority: Major
    • Resolution: Unresolved
    • Affects Version/s: 13.5.0, 13.5.2
    • Fix Version/s: None
    • Component/s: policy, session
    • Labels:
    • Environment:
      CentOS 6
      Java version "1.8.0_25"
      Apache Tomcat 7.0.65
      OpenAM 13.5.2
      Apache 2.4
      ampolicyagent 3.3
      Google Chrome 60.0.3112.90
    • Support Ticket IDs:


      Bug description

      I see "Session Upgrade fails since user is different than original authenticated user" in Google Chrome while trying to upgrade session create on first AM node on second node. Don't see this error in Firefox 54.
      I have added debug files from both OpenAM instances as attachment.
      I'm not able to reproduce this without step 1 bellow.
      I don't see error when working with only one AM.

      How to reproduce the issue

      Copying first part from OPENAM-10997:
      1. Create a policy with "Authentication by Module Instance" environment condition :
      Type : Authentication by Module Instance"
      Authentication Scheme : LDAP
      Application Idle Timeout Scheme : 30
      Application Name "iPlanetAMWebAgentService"
      2. User authenticates on one server (AM#1)
      3. User access protected site
      4. Policy Agent redirect the user to login page
      5. User goes through session upgrade on another server (AM#2)

      Expected behaviour
      Login successful and redirection to protected site
      Current behaviour
      Error "Session Upgrade fails since user is different than original authenticated user" shows. Sometimes it is possible to push login button again few times and session is upgraded. Sometimes it is not, then it was possible to close chromium window and do it again starting on other server (AM#2).

      Work around

      Use Mozilla Firefox not Chrome.




            • Assignee:
              lubomir.mlich Ľubomír Mlích
            • Votes:
              0 Vote for this issue
              1 Start watching this issue


              • Created: