OK. Two things jumped out at me:

 

1.       "Sporadic" almost always means "load balancer". So I'd start
there.

 

2.       It's very likely that you are affected by this issue: 
http://jasig.github.io/cas/development/installation/Troubleshooting-Guide.
html#login-form-clearing-credentials-on-submission

 

 

From: Juan Quintanilla [mailto:[email protected]] 
Sent: Wednesday, July 8, 2015 10:05 AM
To: [email protected]
Subject: Re: [cas-user] CAS User remains on login page

 

So if the user enters bad credentials they receive no message from the
login page about bad credentials nor do I see the transaction in the
catalina.out file.  If the user enters the right credentials I still do
not see the transaction in the catalina.out and the user is redirected
back to the login page.  If they enter the credentials again and hit enter
or login they are redirected back to the login page and there is no
transaction for that user in the log. In the url you see the service that
they are coming from.

 

Only when the user closes the browser and tries again are they able to
access the application, if the user is already logged into an application
that is using CAS they don't have a problem.  It tends to be new users and
its sporadic.

 

Thanks!

 

___________________
Juan Quintanilla

UTS - Enterprise Group

305-348-6573

[email protected] <mailto:[email protected]> 

 

  _____  

From: Misagh Moayyed <[email protected] <mailto:[email protected]> >
Sent: Wednesday, July 8, 2015 12:57 PM
To: [email protected] <mailto:[email protected]> 
Subject: RE: [cas-user] CAS User remains on login page 

 

"If they enter bad credentials no error message is displayed and if they
enter the correct credentials they are redirected back to the CAS login
page."

 

What happens if I enter my credentials correctly, get redirected back to
the CAS login page, and then again enter my credentials? Are you able to
login and get back to the application? 

 

From: Juan Quintanilla [mailto:[email protected]] 
Sent: Wednesday, July 8, 2015 9:53 AM
To: [email protected] <mailto:[email protected]> 
Subject: Re:[cas-user] CAS User remains on login page

 

Hi,

 

So we encountered the issue and I was able to check the http headers, it
seems to pull the login page and  the images but after credentials are
entered and the user hits login or enter there are no further http headers
recorded.  The applications are redirected to the web url which is load
balanced on an F5 if that helps.  I'm trying to see whether I should be
looking towards the CAS application 3.6.0 , tomcat 8, or the F5 to see
what may be causing some random users to experience a dead login page.

Any other suggestions are welcomed.

 

Thanks!

___________________
Juan Quintanilla

UTS - Enterprise Group

305-348-6573

[email protected] <mailto:[email protected]> 

 

  _____  

From: Mailvaganam, Hari <[email protected]
<mailto:[email protected]> >
Sent: Wednesday, July 8, 2015 3:53 AM
To: [email protected] <mailto:[email protected]> 
Subject: RE:[cas-user] CAS User remains on login page 

 

Trace the HTTP headers - may have a clue there? 

 

Sample Firefox
plugin:https://addons.mozilla.org/en-us/firefox/addon/live-http-headers/ 

  _____  

From: Juan Quintanilla [[email protected]]
Sent: Tuesday, July 07, 2015 06:53
To: [email protected] <mailto:[email protected]> 
Subject: [cas-user] CAS User remains on login page

Hi,

 

We currently deployed CAS 3.6.0 with backend ldap and oracle Db for
ticketing and everything seems to be working great, but on occasion we
have had some users who have gone to a particular site report that when
they are redirected to the CAS Login page from the client application they
are not able to login.  If they enter bad credentials no error message is
displayed and if they enter the correct credentials they are redirected
back to the CAS login page.

 

When I check the CAS server logs I do not see any transactions for the
user nor do I see failed authentication attempts for Ldap, its as if the
communication is not even reaching the server, the tomcat logs don't
report any errors for the times when the issue is encountered.  It seems
to happen sporadically since other users have no problem logging in.  Once
the user closers their browser or tab and tries again they are able to
login.

 

Just wanted to see if anyone has encountered something similar in their
environment, I'm thinking it has to be something relating to the
networking side.

 

___________________
Juan Quintanilla

[email protected] <mailto:[email protected]> 

-- 
You are currently subscribed to [email protected]
<mailto:[email protected]>  as: [email protected]
<mailto:[email protected]> 
To unsubscribe, change settings or access archives, see
http://www.ja-sig.org/wiki/display/JSG/cas-user
<https://urldefense.proofpoint.com/v2/url?u=http-3A__www.ja-2Dsig.org_wiki
_display_JSG_cas-2Duser&d=AwMFAg&c=1QsCMERiq7JOmEnKpsSyjg&r=NauC5-J1X4CCd2
5sdSxQCA&m=4V-88VYYRdcxsAvjCGL2viYCCcFTZJfN8n4EZJyKGaM&s=LzuDiXOSEkkQInV2X
FL8BraMKD8uyfNONsm0tkLwM4U&e=> 
-- 
You are currently subscribed to [email protected]
<mailto:[email protected]>  as: [email protected]
<mailto:[email protected]> 
To unsubscribe, change settings or access archives, see
http://www.ja-sig.org/wiki/display/JSG/cas-user
<https://urldefense.proofpoint.com/v2/url?u=http-3A__www.ja-2Dsig.org_wiki
_display_JSG_cas-2Duser&d=AwMFAg&c=1QsCMERiq7JOmEnKpsSyjg&r=NauC5-J1X4CCd2
5sdSxQCA&m=4V-88VYYRdcxsAvjCGL2viYCCcFTZJfN8n4EZJyKGaM&s=LzuDiXOSEkkQInV2X
FL8BraMKD8uyfNONsm0tkLwM4U&e=> 
 
-- 
You are currently subscribed to [email protected]
<mailto:[email protected]>  as: [email protected]
<mailto:[email protected]> 
To unsubscribe, change settings or access archives, see
http://www.ja-sig.org/wiki/display/JSG/cas-user
<https://urldefense.proofpoint.com/v2/url?u=http-3A__www.ja-2Dsig.org_wiki
_display_JSG_cas-2Duser&d=AwMFAg&c=1QsCMERiq7JOmEnKpsSyjg&r=NauC5-J1X4CCd2
5sdSxQCA&m=4V-88VYYRdcxsAvjCGL2viYCCcFTZJfN8n4EZJyKGaM&s=LzuDiXOSEkkQInV2X
FL8BraMKD8uyfNONsm0tkLwM4U&e=> 
-- 
You are currently subscribed to [email protected]
<mailto:[email protected]>  as: [email protected]
<mailto:[email protected]> 
To unsubscribe, change settings or access archives, see
http://www.ja-sig.org/wiki/display/JSG/cas-user
 
-- 
You are currently subscribed to [email protected]
<mailto:[email protected]>  as: [email protected]
<mailto:[email protected]> 
To unsubscribe, change settings or access archives, see
http://www.ja-sig.org/wiki/display/JSG/cas-user

-- 
You are currently subscribed to [email protected] as: 
[email protected]
To unsubscribe, change settings or access archives, see 
http://www.ja-sig.org/wiki/display/JSG/cas-user

Reply via email to