Andrea Veri commented:
This was fixed:
for some reason I did configure the LDAP backend to use an auth server located in another DC, instead of the closer one, so in case VPN was flapping auth might have had hiccups I also believe the cookies might have been "compromised" by the impersonation, i.e they became invalid but were never cleaned out by a proper log out