Digital Developer Conference: a FREE half-day online conference focused on AI & Cloud – North America: Nov 2 – India: Nov 9 – Europe: Nov 14 – Asia Nov 23 Register now

Close outline
  • United States
IBM?
  • Site map
IBM?
  • Marketplace

  • Close
    Search
  • Sign in
    • Sign in
    • Register
  • IBM Navigation
IBM Developer Answers
  • Spaces
    • Blockchain
    • IBM Cloud platform
    • Internet of Things
    • Predictive Analytics
    • Watson
    • See all spaces
  • Tags
  • Users
  • Badges
  • FAQ
  • Help
Close

Name

Community

  • Learn
  • Develop
  • Connect

Discover IBM

  • ConnectMarketplace
  • Products
  • Services
  • Industries
  • Careers
  • Partners
  • Support
10.190.13.195

Refine your search by using the following advanced search options.

Criteria Usage
Questions with keyword1 or keyword2 keyword1 keyword2
Questions with a mandatory word, e.g. keyword2 keyword1 +keyword2
Questions excluding a word, e.g. keyword2 keyword1 -keyword2
Questions with keyword(s) and a specific tag keyword1 [tag1]
Questions with keyword(s) and either of two or more specific tags keyword1 [tag1] [tag2]
To search for all posts by a user or all posts with a specific tag, start typing and choose from the suggestion list. Do not use a plus or minus sign with a tag, e.g., +[tag1].
  • Ask a question

How can I avoid SESN0008E errors after the LTPA token expires?

2000000MY6 gravatar image
Question by JMW98  (1501) | Sep 17, 2015 at 07:45 AM portalsession

If a user works continuously, without logging out or leaving the session inactive long enough to trigger the inactive session timeout, the LTPA token will eventually expire (by default, after 2 hours). The next request by the user would be with an expired LTPA token and with a JSESSIONID associated with the previously-logged-in user.

When the server receives a request with an expired LtpaToken2, it considers the user to be anonymous / unauthenticated. If the server receives a request from an anonymous user with the JSESSIONID of a previously-logged-in user, and if security integration is enabled (it is enabled, by default, in the latest versions of WAS), then WebSphere Application Server will throw an error/exception like:

Error 500: com.ibm.websphere.servlet.UnauthorizedSessionRequestException: SESN0008E: A user authenticated as anonymous has attempted to access a session owned by user: defaultWIMFileBasedRealm/uid=wpadmin,o=defaultWIMFileBasedRealm

How can such an error be avoided?

People who like this

  0
Comment
10 |3000 characters needed characters left characters exceeded
  • Viewable by all users
  • Viewable by moderators
  • Viewable by moderators and the original poster

1 reply

  • Sort: 
2000000MY6 gravatar image
Accepted answer

Answer by JMW98 (1501) | Sep 17, 2015 at 07:52 AM

Setting the session management custom property InvalidateOnUnauthorizedSessionRequestException=true per:

http://www-01.ibm.com/support/knowledgecenter/SSAW57_8.5.5/com.ibm.websphere.nd.doc/ae/rprs_custom_properties.html?cp=SSAW57_8.5.5%2F1-19-6-959&lang=en

lets you avoid the error. However, you should consider your session management requirements before setting this. By destroying the session, you could break such functionality as session persistence:

http://www-01.ibm.com/support/knowledgecenter/SSHRKX_8.5.0/mp/admin-system/adcfgpss_adm_define.dita

You may also choose to extend the LTPA expiration (e.g. to span users' shifts) to avoid this error. Extending LTPA expiration alone only delays the error. Consider your security requirements when deciding how long LTPA tokens should be valid.

Comment
Richard Lesses

People who like this

  1   Share
10 |3000 characters needed characters left characters exceeded
  • Viewable by all users
  • Viewable by moderators
  • Viewable by moderators and the original poster

Follow this question

48 people are following this question.

Answers

Answers & comments

Related questions

Why is my WEF application throwing "The Specified action main was not found" exception? 1 Answer

How to resolve OutOfMemory error after enabling memory-to-memory replication? 1 Answer

How can we prevent the Cache ID from changing and impacting the session contents? 1 Answer

BPM Process Portal session timeout 1 Answer

Is it possible to run multiple XMLAccess sessions on the same time ? 1 Answer

  • Contact
  • Privacy
  • IBM Developer Terms of use
  • Accessibility
  • Report Abuse
  • Cookie Preferences

Powered by AnswerHub

Authentication check. Please ignore.
  • Anonymous
  • Sign in
  • Create
  • Ask a question
  • Spaces
  • API Connect
  • Analytic Hybrid Cloud Core
  • Application Performance Management
  • Appsecdev
  • BPM
  • Blockchain
  • Business Transaction Intelligence
  • CAPI
  • CAPI SNAP
  • CICS
  • Cloud Analytics
  • Cloud Automation
  • Cloud Object Storage
  • Cloud marketplace
  • Collaboration
  • Content Services (ECM)
  • Continuous Testing
  • Courses
  • Customer Experience Analytics
  • DB2 LUW
  • Data and AI
  • DataPower
  • Decision Optimization
  • DevOps Build
  • DevOps Services
  • Developers IBM MX
  • Digital Commerce
  • Digital Experience
  • Finance
  • Global Entrepreneur Program
  • Hadoop
  • Hybrid Cloud Core
  • Hyper Protect
  • IBM Cloud platform
  • IBM Design
  • IBM Forms Experience Builder
  • IBM Maximo Developer
  • IBM StoredIQ
  • IBM StoredIQ-Cartridges
  • IIDR
  • ITOA
  • InformationServer
  • Integration Bus
  • Internet of Things
  • Kenexa
  • Linux on Power
  • LinuxONE
  • MDM
  • Mainframe
  • Messaging
  • Node.js
  • ODM
  • Open
  • PartnerWorld Developer Support
  • PowerAI
  • PowerVC
  • Predictive Analytics
  • Product Insights
  • PureData for Analytics
  • Push
  • QRadar App Development
  • Run Book Automation
  • Search Insights
  • Security Core
  • Storage
  • Storage Core
  • Streamsdev
  • Supply Chain Business Network
  • Supply Chain Insights
  • Swift
  • UBX Capture
  • Universal Behavior Exchange
  • UrbanCode
  • WASdev
  • WSRR
  • Watson
  • Watson Campaign Automation
  • Watson Content Hub
  • Watson Marketing Insights
  • dW Answers Help
  • dW Premium
  • developerWorks Sandbox
  • developerWorks Team
  • Watson Health
  • More
  • Tags
  • Questions
  • Users
  • Badges