<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Question Re: SSL session timeout even though stickiness=session ID in Technology Q&amp;A</title>
    <link>https://community.sap.com/t5/technology-q-a/ssl-session-timeout-even-though-stickiness-session-id/qaa-p/826302#M264852</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does anyone know how to control the behavior of the Distributed Session Manager in the Portal (SP1)? Specifically, whether it can associate a session with multiple connections, say an old one then be able to use a new one?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 05 May 2004 19:12:11 GMT</pubDate>
    <dc:creator>former_member1090788</dc:creator>
    <dc:date>2004-05-05T19:12:11Z</dc:date>
    <item>
      <title>SSL session timeout even though stickiness=session ID</title>
      <link>https://community.sap.com/t5/technology-q-a/ssl-session-timeout-even-though-stickiness-session-id/qaq-p/826301</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;EP6 SP1 Patch 1 HF9&lt;/P&gt;&lt;P&gt;We're having a problem trying to use SSL session ID as the stickiness method on the load balancer. While we have "everything" set to at least 1 hour for inactivity timeout on the load balancer (Cisco 11050), web server and J2EE (see below), we experience the following symptom: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. User logs in successfully to portal using SSL, using IE 6 SP1, with latest patches. They're sent to website #1. Load balancer creates entry in sticky table for that session ID. &lt;/P&gt;&lt;P&gt;2. User does nothing for a period of time less than 1 hour. Seems like less than 5 minutes, we're ok, &amp;gt;5 minutes to 1 hour is the problem, but not consistent. &lt;/P&gt;&lt;P&gt;3. User clicks again in the portal on TLN (native portal page, not even ITS iView or homegrown iView), and after a very long pause (say 30-60 seconds), we finally get either a "action canceled" or "page cannot be displayed" error. &lt;/P&gt;&lt;P&gt;4. Next click allows user to continue to destination without logging in, like nothing was ever wrong. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My feeling is that:&lt;/P&gt;&lt;P&gt;- it's either browser-related, IIS web server related, or J2EE server related. If the inactivity was longer than an hour, we'd be prompted with the login page again, and we'd be load balanced again, potentially to a different website and receive a new session ID. &lt;/P&gt;&lt;P&gt;- since I'm NOT being prompted to login, my session must still be good according to our Web Access Management plugin and the load balancer. J2EE accepts the subsequent click (and we're sent back to same website and thus same J2EE server), so the load balancer sticky entry is still valid. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have set: &lt;/P&gt;&lt;P&gt;Load balancer session inactivity timeout = 1 hour&lt;/P&gt;&lt;P&gt;Load balancer max session lifetime = 2 hours&lt;/P&gt;&lt;P&gt;WAM plugin inactivity timeout = 1 hour&lt;/P&gt;&lt;P&gt;WAM max session lifetime = 2 hours&lt;/P&gt;&lt;P&gt;Web server SChannel ServerCacheTime (SSL session expiration) = 2 hours (this didn't seem to help)&lt;/P&gt;&lt;P&gt;J2EE http service keepalivetimeout = 1 hour&lt;/P&gt;&lt;P&gt;SAP cookie lifetime = 8 hours&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any we're missing? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the meantime, is there anything you can suggest to identify the problem, or if other customers are successfully using SSL session ID as the stickiness method? We'd prefer to use session ID instead of source IP if at all possible. The HA Guide for EP6 only mentions source IP (not good for customers with proxies, ISP's or mega-proxies) and cookie based stickiness (doesn't work with SSL). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Apr 2004 22:29:41 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/ssl-session-timeout-even-though-stickiness-session-id/qaq-p/826301</guid>
      <dc:creator>former_member1090788</dc:creator>
      <dc:date>2004-04-29T22:29:41Z</dc:date>
    </item>
    <item>
      <title>Re: SSL session timeout even though stickiness=session ID</title>
      <link>https://community.sap.com/t5/technology-q-a/ssl-session-timeout-even-though-stickiness-session-id/qaa-p/826302#M264852</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does anyone know how to control the behavior of the Distributed Session Manager in the Portal (SP1)? Specifically, whether it can associate a session with multiple connections, say an old one then be able to use a new one?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 May 2004 19:12:11 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/ssl-session-timeout-even-though-stickiness-session-id/qaa-p/826302#M264852</guid>
      <dc:creator>former_member1090788</dc:creator>
      <dc:date>2004-05-05T19:12:11Z</dc:date>
    </item>
    <item>
      <title>Re: SSL session timeout even though stickiness=session ID</title>
      <link>https://community.sap.com/t5/technology-q-a/ssl-session-timeout-even-though-stickiness-session-id/qaa-p/826303#M264853</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jim - I'm new to Cisco and am focusing on our solutions for SAP customers, specifically for the load balancing products. Are there any issues you have where I might be able to help out. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If so, please contact me at dosilver@cisco.com or +1 650-346-8945..... Doug&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 26 Mar 2006 01:16:22 GMT</pubDate>
      <guid>https://community.sap.com/t5/technology-q-a/ssl-session-timeout-even-though-stickiness-session-id/qaa-p/826303#M264853</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2006-03-26T01:16:22Z</dc:date>
    </item>
  </channel>
</rss>

