We are now using
cas.audit.engine.alternate-client-addr-header-name
property with a custom header that has the clients real ip.
X-FORWAREDED-FOR is the header sending two IPs.
On Thursday, December 7, 2023 at 1:31:56 PM UTC-6 Pablo Vidaurri wrote:
> Seeing sessions get dropped prematurely, I see messages from CAS that TGC
> cookie is based partly on client ip address. In log, I am seeing client id
> along with the edge server IP. This seems to be having an impact when a
> user is routed thru a different edge sever and causing the session to be
> lost. But looking at inspektr code I see it is setting this based of
> clientInfo.getClientIpAddress() which is only retuning the actual client id.
>
>
> Has anyone else experienced this issue? I see someone suggested
> pin-to-session property but I really do not want to disable that.
>
>
> =============================================================
> WHO: audit:unknown WHAT:
> {source=RankedMultifactorAuthenticationProviderWebflowEventResolver,
> event=success, timestamp=Thu Dec 07 00:00:01 MST 2023} ACTION:
> AUTHENTICATION_EVENT_TRIGGERED APPLICATION: CAS WHEN: Thu Dec 07 00:00:01
> MST 2023 CLIENT IP ADDRESS: 123.xx.xx.xxx, 23.xx.xx.xx SERVER IP ADDRESS:
> www.zzzzz.com <https://www.nxp.com>
>
> =============================================================
>
>
> -psv
>
--
- Website: https://apereo.github.io/cas
- Gitter Chatroom: https://gitter.im/apereo/cas
- List Guidelines: https://goo.gl/1VRrw7
- Contributions: https://goo.gl/mh7qDG
---
You received this message because you are subscribed to the Google Groups "CAS
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to [email protected].
To view this discussion on the web visit
https://groups.google.com/a/apereo.org/d/msgid/cas-user/473b9c92-d0d2-46d0-a0d2-474033793646n%40apereo.org.