Previous Topic: LogRollOverSize Logging Parameter Incorrectly Accepts Negative, Character, and Decimal Values and Does Not Display the Default Value in Logs (27390)

Next Topic: Host Configuration File Compatibility

Identity Asserter Not Propagating New User’s Identify into the WebLogic Server After Logoff and Login (36161)

Symptom:

The following steps describe this limitation:

  1. In single Web browser session, one user was successfully authenticated, authorized, and granted access to a Web application by SiteMinder and the WebLogic Server.
  2. The user logged out of SiteMinder using the logoff URI.
  3. In the same Web browser session, a second user was successfully authenticated and authorized by SiteMinder and the WebLogic Server.
  4. When the second user accessed the same Web Application, the WebLogic Server identified him as the first user, based on the Web browser headers.

The Identity Asserter log file did not show that the identity of the second user was ever asserted. Further, the WebLogic Server never issued a new JSession cookie. The first user was logged out of the SiteMinder session but not the WebLogic Server session. In this scenario, the SiteMinder Agent for BEA WebLogic functions as designed since the synchronization of the SiteMinder logoff and WebLogic logoff is not required.

Solution:

As a workaround, do one of the following:


Copyright © 2010 CA. All rights reserved. Email CA about this topic