User is prompted to login to WebAccess multiple times

(Last modified: 18Apr2003)

This document (10051758) is provided subject to the disclaimer at the end of this document.

fact

Novell GroupWise 6

Novell GroupWise 5.5 EP Support Pack 1

Novell GroupWise 5.5

Novell GroupWise WebAccess

Novell BorderManager 3.5

HTTP Proxy

HTTP Acceleration

Proxy Server

symptom

User is prompted to login to WebAccess multiple times

Error: "Your login is not current. Please log in again"

User keeps getting asked to authenticate while trying to access email through WebAccess

cause

When doing reverse HTTP Proxy or HTTP Acceleration with BorderManager on GroupWise WebAccess it causes the user to have to login twice.  Once to render the cached session invalid and once to login.

fix

Workaround is to not accelerate WebAccess.  This issue has been reported to development.

cause

Another possible cause is a proxy cache problem with the proxy server.  (It may or may not be BorderManager)

fix

Fix the proxy problem with the firewall vendor.

cause

Transparent Proxy for BorderManager, BorderManager Access Control Rules and an internal Webserver can have this problem.

fix

1. Goto the details of the BorderManager server object in NWAdmin.
2. Select the BorderManager Setup tab | Transparent Proxy | Exception IP Address List.
3. Put in the IP address to the Webserver.

cause

WebAccess uses the client IP address as added security to help verify session requests.  Since many proxies are setup with multiple proxy servers to help with load balancing, it is common occurrence for a WebAccess user's session to originate from one proxy server and a later request during the same WebAccess session to be routed through a different proxy server.  This will cause WebAccess to force the user to re-authenticate.  An option in the WEBACC.CFG file determines whether the client's IP address is used to validate the user session. With Enhancement Pack SP1, this setting can now be configured by the administrator. The default is to require the IP Address validation.

fix

To disable WebAccess IP Address validation, change the value of the "Security.UseClientIP.enable" setting in the WEBACC.CFG file from "true" to "false" (as in the following example): Security.UseClientIP.enable=false.
WARNING: Setting this to false will potentially allow someone to connect to user's email accounts while they are currently logged in and their session is active by using the url to a message or the mailbox. The url can be logged by webservers to which the user connects by clicking on a hyperlink in a mail message, if the webserver logs referral urls. This could also be found through a packet trace. Additionally, setting up a secure web server, using SSL for example, will often resolve this problem as well since proxy servers used by ISPs commonly behave differently during secure transactions.
Another option to secure WebAccess is to secure the webserver with NDS authentication or some kind of access control.
NOTE: You must have Support Pack 1 for the Enhancement Pack installed for this setting to take effect.

document

Document Title: User is prompted to login to WebAccess multiple times
Document ID: 10051758
Solution ID: NOVL5959
Creation Date: 12Apr2000
Modified Date: 18Apr2003
Novell Product Class:Groupware
NetWare
Novonyx

disclaimer

The Origin of this information may be internal or external to Novell. Novell makes all reasonable efforts to verify this information. However, the information provided in this document is for your information only. Novell makes no explicit or implied claims to the validity of this information.
Any trademarks referenced in this document are the property of their respective owners. Consult your product manuals for complete trademark information.