<html>
<head>
<meta http-equiv="Content-Type" content="text/html;
charset=windows-1252">
</head>
<body>
<p>Ok, forget about the previous message, it worked when I created
the file.</p>
<p>And now the IDP has started.</p>
<p>I just have two errors I don't really understand, first one is
about opt/shibboleth-idp/credentials/idp-signing-rs.jwk but I
found nothing about it yet.<br>
</p>
<p><br>
</p>
<p>shib_idp_container | java.io.FileNotFoundException: class path
resource [opt/shibboleth-idp/credentials/idp-signing-rs.jwk]
cannot be opened because it does not exist<br>
shib_idp_container | at
org.springframework.core.io.ClassPathResource.getInputStream(ClassPathResource.java:180)<br>
shib_idp_container | 2020-09-07 13:03:27,443 - - WARN
[net.shibboleth.ext.spring.context.FilesystemGenericApplicationContext:558]
- Exception encountered during context initialization - cancelling
refresh attempt:
org.springframework.beans.factory.BeanCreationException: Error
creating bean with name 'profileResponders': Cannot resolve
reference to bean 'OIDC.SSO' while setting bean property
'sourceMap'; nested exception is
org.springframework.beans.factory.BeanCreationException: Error
creating bean with name 'OIDC.SSO' defined in file
[/opt/shibboleth-idp/conf/oidc-relying-party.xml]: Cannot resolve
reference to bean 'shibboleth.oidc.DefaultSecurityConfiguration'
while setting bean property 'securityConfiguration'; nested
exception is
org.springframework.beans.factory.BeanCreationException: Error
creating bean with name
'shibboleth.oidc.DefaultSecurityConfiguration' defined in file
[/opt/shibboleth-idp/conf/oidc-relying-party.xml]: Cannot resolve
reference to bean
'#{'shibboleth.oidc.SigningConfiguration'.trim()}' while setting
bean property 'signatureSigningConfiguration'; nested exception is
org.springframework.beans.factory.BeanCreationException: Error
creating bean with name 'shibboleth.oidc.SigningConfiguration'
defined in file [/opt/shibboleth-idp/conf/oidc-relying-party.xml]:
Cannot resolve reference to bean
'shibboleth.oidc.SigningCredentials' while setting bean property
'signingCredentials'; nested exception is
org.springframework.beans.factory.BeanCreationException: Error
creating bean with name 'shibboleth.oidc.SigningCredentials':
Cannot resolve reference to bean
'shibboleth.oidc.DefaultRSSigningCredential' while setting bean
property 'sourceList' with key [0]; nested exception is
org.springframework.beans.factory.BeanCreationException: Error
creating bean with name
'shibboleth.oidc.DefaultRSSigningCredential' defined in file
[/opt/shibboleth-idp/conf/credentials-oidc.xml]: Invocation of
init method failed; nested exception is
org.springframework.beans.FatalBeanException: Could not decode
provided KeyFile class path resource
[opt/shibboleth-idp/credentials/idp-signing-rs.jwk]; nested
exception is java.io.FileNotFoundException: class path resource
[opt/shibboleth-idp/credentials/idp-signing-rs.jwk] cannot be
opened because it does not exist<br>
shib_idp_container | 2020-09-07 13:03:27,452 - - ERROR
[net.shibboleth.utilities.java.support.service.AbstractReloadableService:182]
- Service 'shibboleth.RelyingPartyResolverService': Initial load
failed<br>
shib_idp_container |
net.shibboleth.utilities.java.support.service.ServiceException:
org.springframework.beans.factory.BeanCreationException: Error
creating bean with name 'profileResponders': Cannot resolve
reference to bean 'OIDC.SSO' while setting bean property
'sourceMap'; nested exception is
org.springframework.beans.factory.BeanCreationException: Error
creating bean with name 'OIDC.SSO' defined in file
[/opt/shibboleth-idp/conf/oidc-relying-party.xml]: Cannot resolve
reference to bean 'shibboleth.oidc.DefaultSecurityConfiguration'
while setting bean property 'securityConfiguration'; nested
exception is
org.springframework.beans.factory.BeanCreationException: Error
creating bean with name
'shibboleth.oidc.DefaultSecurityConfiguration' defined in file
[/opt/shibboleth-idp/conf/oidc-relying-party.xml]: Cannot resolve
reference to bean
'#{'shibboleth.oidc.SigningConfiguration'.trim()}' while setting
bean property 'signatureSigningConfiguration'; nested exception is
org.springframework.beans.factory.BeanCreationException: Error
creating bean with name 'shibboleth.oidc.SigningConfiguration'
defined in file [/opt/shibboleth-idp/conf/oidc-relying-party.xml]:
Cannot resolve reference to bean
'shibboleth.oidc.SigningCredentials' while setting bean property
'signingCredentials'; nested exception is
org.springframework.beans.factory.BeanCreationException: Error
creating bean with name 'shibboleth.oidc.SigningCredentials':
Cannot resolve reference to bean
'shibboleth.oidc.DefaultRSSigningCredential' while setting bean
property 'sourceList' with key [0]; nested exception is
org.springframework.beans.factory.BeanCreationException: Error
creating bean with name
'shibboleth.oidc.DefaultRSSigningCredential' defined in file
[/opt/shibboleth-idp/conf/credentials-oidc.xml]: Invocation of
init method failed; nested exception is
org.springframework.beans.FatalBeanException: Could not decode
provided KeyFile class path resource
[opt/shibboleth-idp/credentials/idp-signing-rs.jwk]; nested
exception is java.io.FileNotFoundException: class path resource
[opt/shibboleth-idp/credentials/idp-signing-rs.jwk] cannot be
opened because it does not exist<br>
shib_idp_container | at
net.shibboleth.ext.spring.service.ReloadableSpringService.doReload(ReloadableSpringService.java:377)<br>
shib_idp_container | Caused by:
org.springframework.beans.factory.BeanCreationException: Error
creating bean with name 'profileResponders': Cannot resolve
reference to bean 'OIDC.SSO' while setting bean property
'sourceMap'; nested exception is
org.springframework.beans.factory.BeanCreationException: Error
creating bean with name 'OIDC.SSO' defined in file
[/opt/shibboleth-idp/conf/oidc-relying-party.xml]: Cannot resolve
reference to bean 'shibboleth.oidc.DefaultSecurityConfiguration'
while setting bean property 'securityConfiguration'; nested
exception is
org.springframework.beans.factory.BeanCreationException: Error
creating bean with name
'shibboleth.oidc.DefaultSecurityConfiguration' defined in file
[/opt/shibboleth-idp/conf/oidc-relying-party.xml]: Cannot resolve
reference to bean
'#{'shibboleth.oidc.SigningConfiguration'.trim()}' while setting
bean property 'signatureSigningConfiguration'; nested exception is
org.springframework.beans.factory.BeanCreationException: Error
creating bean with name 'shibboleth.oidc.SigningConfiguration'
defined in file [/opt/shibboleth-idp/conf/oidc-relying-party.xml]:
Cannot resolve reference to bean
'shibboleth.oidc.SigningCredentials' while setting bean property
'signingCredentials'; nested exception is
org.springframework.beans.factory.BeanCreationException: Error
creating bean with name 'shibboleth.oidc.SigningCredentials':
Cannot resolve reference to bean
'shibboleth.oidc.DefaultRSSigningCredential' while setting bean
property 'sourceList' with key [0]; nested exception is
org.springframework.beans.factory.BeanCreationException: Error
creating bean with name
'shibboleth.oidc.DefaultRSSigningCredential' defined in file
[/opt/shibboleth-idp/conf/credentials-oidc.xml]: Invocation of
init method failed; nested exception is
org.springframework.beans.FatalBeanException: Could not decode
provided KeyFile class path resource
[opt/shibboleth-idp/credentials/idp-signing-rs.jwk]; nested
exception is java.io.FileNotFoundException: class path resource
[opt/shibboleth-idp/credentials/idp-signing-rs.jwk] cannot be
opened because it does not exist<br>
shib_idp_container | at
org.springframework.beans.factory.support.BeanDefinitionValueResolver.resolveReference(BeanDefinitionValueResolver.java:342)<br>
shib_idp_container | Caused by:
org.springframework.beans.factory.BeanCreationException: Error
creating bean with name 'OIDC.SSO' defined in file
[/opt/shibboleth-idp/conf/oidc-relying-party.xml]: Cannot resolve
reference to bean 'shibboleth.oidc.DefaultSecurityConfiguration'
while setting bean property 'securityConfiguration'; nested
exception is
org.springframework.beans.factory.BeanCreationException: Error
creating bean with name
'shibboleth.oidc.DefaultSecurityConfiguration' defined in file
[/opt/shibboleth-idp/conf/oidc-relying-party.xml]: Cannot resolve
reference to bean
'#{'shibboleth.oidc.SigningConfiguration'.trim()}' while setting
bean property 'signatureSigningConfiguration'; nested exception is
org.springframework.beans.factory.BeanCreationException: Error
creating bean with name 'shibboleth.oidc.SigningConfiguration'
defined in file [/opt/shibboleth-idp/conf/oidc-relying-party.xml]:
Cannot resolve reference to bean
'shibboleth.oidc.SigningCredentials' while setting bean property
'signingCredentials'; nested exception is
org.springframework.beans.factory.BeanCreationException: Error
creating bean with name 'shibboleth.oidc.SigningCredentials':
Cannot resolve reference to bean
'shibboleth.oidc.DefaultRSSigningCredential' while setting bean
property 'sourceList' with key [0]; nested exception is
org.springframework.beans.factory.BeanCreationException: Error
creating bean with name
'shibboleth.oidc.DefaultRSSigningCredential' defined in file
[/opt/shibboleth-idp/conf/credentials-oidc.xml]: Invocation of
init method failed; nested exception is
org.springframework.beans.FatalBeanException: Could not decode
provided KeyFile class path resource
[opt/shibboleth-idp/credentials/idp-signing-rs.jwk]; nested
exception is java.io.FileNotFoundException: class path resource
[opt/shibboleth-idp/credentials/idp-signing-rs.jwk] cannot be
opened because it does not exist<br>
shib_idp_container | at
org.springframework.beans.factory.support.BeanDefinitionValueResolver.resolveReference(BeanDefinitionValueResolver.java:342)<br>
shib_idp_container | Caused by:
org.springframework.beans.factory.BeanCreationException: Error
creating bean with name
'shibboleth.oidc.DefaultSecurityConfiguration' defined in file
[/opt/shibboleth-idp/conf/oidc-relying-party.xml]: Cannot resolve
reference to bean
'#{'shibboleth.oidc.SigningConfiguration'.trim()}' while setting
bean property 'signatureSigningConfiguration'; nested exception is
org.springframework.beans.factory.BeanCreationException: Error
creating bean with name 'shibboleth.oidc.SigningConfiguration'
defined in file [/opt/shibboleth-idp/conf/oidc-relying-party.xml]:
Cannot resolve reference to bean
'shibboleth.oidc.SigningCredentials' while setting bean property
'signingCredentials'; nested exception is
org.springframework.beans.factory.BeanCreationException: Error
creating bean with name 'shibboleth.oidc.SigningCredentials':
Cannot resolve reference to bean
'shibboleth.oidc.DefaultRSSigningCredential' while setting bean
property 'sourceList' with key [0]; nested exception is
org.springframework.beans.factory.BeanCreationException: Error
creating bean with name
'shibboleth.oidc.DefaultRSSigningCredential' defined in file
[/opt/shibboleth-idp/conf/credentials-oidc.xml]: Invocation of
init method failed; nested exception is
org.springframework.beans.FatalBeanException: Could not decode
provided KeyFile class path resource
[opt/shibboleth-idp/credentials/idp-signing-rs.jwk]; nested
exception is java.io.FileNotFoundException: class path resource
[opt/shibboleth-idp/credentials/idp-signing-rs.jwk] cannot be
opened because it does not exist<br>
shib_idp_container | at
org.springframework.beans.factory.support.BeanDefinitionValueResolver.resolveReference(BeanDefinitionValueResolver.java:342)<br>
shib_idp_container | Caused by:
org.springframework.beans.factory.BeanCreationException: Error
creating bean with name 'shibboleth.oidc.SigningConfiguration'
defined in file [/opt/shibboleth-idp/conf/oidc-relying-party.xml]:
Cannot resolve reference to bean
'shibboleth.oidc.SigningCredentials' while setting bean property
'signingCredentials'; nested exception is
org.springframework.beans.factory.BeanCreationException: Error
creating bean with name 'shibboleth.oidc.SigningCredentials':
Cannot resolve reference to bean
'shibboleth.oidc.DefaultRSSigningCredential' while setting bean
property 'sourceList' with key [0]; nested exception is
org.springframework.beans.factory.BeanCreationException: Error
creating bean with name
'shibboleth.oidc.DefaultRSSigningCredential' defined in file
[/opt/shibboleth-idp/conf/credentials-oidc.xml]: Invocation of
init method failed; nested exception is
org.springframework.beans.FatalBeanException: Could not decode
provided KeyFile class path resource
[opt/shibboleth-idp/credentials/idp-signing-rs.jwk]; nested
exception is java.io.FileNotFoundException: class path resource
[opt/shibboleth-idp/credentials/idp-signing-rs.jwk] cannot be
opened because it does not exist<br>
shib_idp_container | at
org.springframework.beans.factory.support.BeanDefinitionValueResolver.resolveReference(BeanDefinitionValueResolver.java:342)<br>
shib_idp_container | Caused by:
org.springframework.beans.factory.BeanCreationException: Error
creating bean with name 'shibboleth.oidc.SigningCredentials':
Cannot resolve reference to bean
'shibboleth.oidc.DefaultRSSigningCredential' while setting bean
property 'sourceList' with key [0]; nested exception is
org.springframework.beans.factory.BeanCreationException: Error
creating bean with name
'shibboleth.oidc.DefaultRSSigningCredential' defined in file
[/opt/shibboleth-idp/conf/credentials-oidc.xml]: Invocation of
init method failed; nested exception is
org.springframework.beans.FatalBeanException: Could not decode
provided KeyFile class path resource
[opt/shibboleth-idp/credentials/idp-signing-rs.jwk]; nested
exception is java.io.FileNotFoundException: class path resource
[opt/shibboleth-idp/credentials/idp-signing-rs.jwk] cannot be
opened because it does not exist<br>
shib_idp_container | at
org.springframework.beans.factory.support.BeanDefinitionValueResolver.resolveReference(BeanDefinitionValueResolver.java:342)<br>
shib_idp_container | Caused by:
org.springframework.beans.factory.BeanCreationException: Error
creating bean with name
'shibboleth.oidc.DefaultRSSigningCredential' defined in file
[/opt/shibboleth-idp/conf/credentials-oidc.xml]: Invocation of
init method failed; nested exception is
org.springframework.beans.FatalBeanException: Could not decode
provided KeyFile class path resource
[opt/shibboleth-idp/credentials/idp-signing-rs.jwk]; nested
exception is java.io.FileNotFoundException: class path resource
[opt/shibboleth-idp/credentials/idp-signing-rs.jwk] cannot be
opened because it does not exist<br>
shib_idp_container | at
org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.initializeBean(AbstractAutowireCapableBeanFactory.java:1796)<br>
shib_idp_container | Caused by:
org.springframework.beans.FatalBeanException: Could not decode
provided KeyFile class path resource
[opt/shibboleth-idp/credentials/idp-signing-rs.jwk]; nested
exception is java.io.FileNotFoundException: class path resource
[opt/shibboleth-idp/credentials/idp-signing-rs.jwk] cannot be
opened because it does not exist<br>
shib_idp_container | at
org.geant.idpextension.oidc.profile.spring.factory.BasicJWKCredentialFactoryBean.doCreateInstance(BasicJWKCredentialFactoryBean.java:83)<br>
shib_idp_container | Caused by: java.io.FileNotFoundException:
class path resource
[opt/shibboleth-idp/credentials/idp-signing-rs.jwk] cannot be
opened because it does not exist<br>
shib_idp_container | at
org.springframework.core.io.ClassPathResource.getInputStream(ClassPathResource.java:180)<br>
<br>
shib_idp_container | 2020-09-07 13:03:46,626 - 127.0.0.1 - ERROR
[org.apache.velocity.loader:351] - ResourceManager: unable to find
resource 'status.vm' in any resource loader.<br>
^CGracefully stopping... (press Ctrl+C again to force)<br>
</p>
<p><br>
</p>
<p><br>
</p>
<p><br>
</p>
<p><br>
</p>
<div class="moz-cite-prefix">Le 07/09/2020 à 14:57, Julien Cochennec
a écrit :<br>
</div>
<blockquote type="cite"
cite="mid:e93ca36f-f11f-ac54-f2a2-6a76ccad8e85@ac-orleans-tours.fr">
<meta http-equiv="Content-Type" content="text/html;
charset=windows-1252">
<p>The CSCFI Image works great, thanks, I just had to add a
parameter to build.sh to make it silent :</p>
<p>RUN /opt/shibboleth-idp/bin/build.sh
-Didp.target.dir=/opt/shibboleth-idp<br>
</p>
<p>Now I have another problem that looks like a file or a
permission is missing (see below for stack trace).<br>
</p>
<p>java.io.FileNotFoundException:
/opt/shibboleth-idp/jetty-base/jetty.state (Permission denied)</p>
<p>Do I have to create this file manually? If so, which
permissions should I use?<br>
</p>
<p><br>
</p>
<p>Step 16/16 : RUN /opt/jetty-home/bin/jetty.sh restart<br>
---> Running in 23f1215149e6<br>
Stopping Jetty: ERROR: no pid found at /var/run/jetty/jetty.pid<br>
Starting Jetty: 2020-09-07 12:43:59.480:<a
class="moz-txt-link-freetext" href="INFO::main"
moz-do-not-send="true">INFO::main</a>: Logging initialized
@1198ms to org.eclipse.jetty.util.log.StdErrLog<br>
2020-09-07 12:44:00.481:<a class="moz-txt-link-freetext"
href="INFO:oejs.SetUIDListener:main" moz-do-not-send="true">INFO:oejs.SetUIDListener:main</a>:
Setting umask=02<br>
2020-09-07 12:44:00.554:<a class="moz-txt-link-freetext"
href="INFO:oejs.SetUIDListener:main" moz-do-not-send="true">INFO:oejs.SetUIDListener:main</a>:
Opened ServerConnector@7975d1d8{SSL, (ssl, alpn,
h2)}{0.0.0.0:8443}<br>
2020-09-07 12:44:00.557:<a class="moz-txt-link-freetext"
href="INFO:oejs.SetUIDListener:main" moz-do-not-send="true">INFO:oejs.SetUIDListener:main</a>:
Opened ServerConnector@18f8cd79{HTTP/1.1, (http/1.1,
h2c)}{0.0.0.0:8080}<br>
2020-09-07 12:44:00.558:<a class="moz-txt-link-freetext"
href="INFO:oejs.SetUIDListener:main" moz-do-not-send="true">INFO:oejs.SetUIDListener:main</a>:
Setting UID=1000<br>
2020-09-07
12:44:00.576:WARN:oejuc.FileNoticeLifeCycleListener:main: <br>
java.io.FileNotFoundException:
/opt/shibboleth-idp/jetty-base/jetty.state (Permission denied)<br>
at java.base/java.io.FileOutputStream.open0(Native Method)<br>
at
java.base/java.io.FileOutputStream.open(FileOutputStream.java:298)<br>
at
java.base/java.io.FileOutputStream.<init>(FileOutputStream.java:237)<br>
at
java.base/java.io.FileOutputStream.<init>(FileOutputStream.java:158)<br>
at
java.base/java.io.FileWriter.<init>(FileWriter.java:82)<br>
at
org.eclipse.jetty.util.component.FileNoticeLifeCycleListener.writeState(FileNoticeLifeCycleListener.java:44)<br>
at
org.eclipse.jetty.util.component.FileNoticeLifeCycleListener.lifeCycleStarting(FileNoticeLifeCycleListener.java:57)<br>
at
org.eclipse.jetty.util.component.AbstractLifeCycle.setStarting(AbstractLifeCycle.java:204)<br>
at
org.eclipse.jetty.util.component.AbstractLifeCycle.start(AbstractLifeCycle.java:71)<br>
at
org.eclipse.jetty.xml.XmlConfiguration.lambda$main$1(XmlConfiguration.java:1929)<br>
at
java.base/java.security.AccessController.doPrivileged(Native
Method)<br>
at
org.eclipse.jetty.xml.XmlConfiguration.main(XmlConfiguration.java:1878)<br>
at
java.base/jdk.internal.reflect.NativeMethodAccessorImpl.invoke0(Native
Method)<br>
at
java.base/jdk.internal.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62)<br>
at
java.base/jdk.internal.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)<br>
at
java.base/java.lang.reflect.Method.invoke(Method.java:566)<br>
at org.eclipse.jetty.start.Main.invokeMain(Main.java:218)<br>
at org.eclipse.jetty.start.Main.start(Main.java:491)<br>
at org.eclipse.jetty.start.Main.main(Main.java:77)<br>
2020-09-07 12:44:00.586:<a class="moz-txt-link-freetext"
href="INFO:oejs.Server:main" moz-do-not-send="true">INFO:oejs.Server:main</a>:
jetty-9.4.29.v20200521; built: 2020-05-21T17:20:40.598Z; git:
77c232aed8a45c818fd27232278d9f95a021095e; jvm
11.0.7+11-alpine-r1<br>
2020-09-07 12:44:00.613:<a class="moz-txt-link-freetext"
href="INFO:oejdp.ScanningAppProvider:main"
moz-do-not-send="true">INFO:oejdp.ScanningAppProvider:main</a>:
Deployment monitor [<a class="moz-txt-link-freetext"
href="file:///opt/shibboleth-idp/jetty-base/webapps/"
moz-do-not-send="true">file:///opt/shibboleth-idp/jetty-base/webapps/</a>]
at interval 1<br>
. . 2020-09-07 12:44:08.127:<a class="moz-txt-link-freetext"
href="INFO:oeja.AnnotationConfiguration:main"
moz-do-not-send="true">INFO:oeja.AnnotationConfiguration:main</a>:
Scanning elapsed time=4429ms<br>
2020-09-07 12:44:08.802:<a class="moz-txt-link-freetext"
href="INFO:oejshC.idp:main" moz-do-not-send="true">INFO:oejshC.idp:main</a>:
No Spring WebApplicationInitializer types detected on classpath<br>
2020-09-07 12:44:09.454:<a class="moz-txt-link-freetext"
href="INFO:oejs.session:main" moz-do-not-send="true">INFO:oejs.session:main</a>:
DefaultSessionIdManager workerName=node0<br>
2020-09-07 12:44:09.456:<a class="moz-txt-link-freetext"
href="INFO:oejs.session:main" moz-do-not-send="true">INFO:oejs.session:main</a>:
No SessionScavenger set, using defaults<br>
2020-09-07 12:44:09.461:<a class="moz-txt-link-freetext"
href="INFO:oejs.session:main" moz-do-not-send="true">INFO:oejs.session:main</a>:
node0 Scavenging every 600000ms<br>
2020-09-07 12:44:09.517:<a class="moz-txt-link-freetext"
href="INFO:oejshC.idp:main" moz-do-not-send="true">INFO:oejshC.idp:main</a>:
Initializing Spring root WebApplicationContext<br>
. . Warning: Nashorn engine is planned to be removed from a
future JDK release<br>
. . Warning: Nashorn engine is planned to be removed from a
future JDK release<br>
. . 2020-09-07 12:44:31.630:<a class="moz-txt-link-freetext"
href="INFO:oejshC.idp:main" moz-do-not-send="true">INFO:oejshC.idp:main</a>:
Initializing Spring DispatcherServlet 'idp'<br>
2020-09-07 12:44:34.098:<a class="moz-txt-link-freetext"
href="INFO:oejsh.ContextHandler:main" moz-do-not-send="true">INFO:oejsh.ContextHandler:main</a>:
Started o.e.j.w.WebAppContext@29a5f4e7{Shibboleth Identity
Provider,/idp,[<a class="moz-txt-link-freetext"
href="file:///tmp/jetty-0_0_0_0-8443-idp_war-_idp-any-2395631551190150044.dir/webinf/"
moz-do-not-send="true">file:///tmp/jetty-0_0_0_0-8443-idp_war-_idp-any-2395631551190150044.dir/webinf/</a>,
<a class="moz-txt-link-freetext"
href="jar:file:///opt/shibboleth-idp/war/idp.war!/"
moz-do-not-send="true">jar:file:///opt/shibboleth-idp/war/idp.war!/</a>],AVAILABLE}{/opt/shibboleth-idp/war/idp.war}<br>
2020-09-07 12:44:34.144:<a class="moz-txt-link-freetext"
href="INFO:oejus.SslContextFactory:main"
moz-do-not-send="true">INFO:oejus.SslContextFactory:main</a>:
x509=X509@46f77687(jetty,h=[jetty.eclipse.org],w=[]) for
Server@74948d11[provider=null,keyStore=<a
class="moz-txt-link-freetext"
href="file:///opt/shibboleth-idp/jetty-base/etc/keystore,trustStore=file:///opt/shibboleth-idp/jetty-base/etc/keystore"
moz-do-not-send="true">file:///opt/shibboleth-idp/jetty-base/etc/keystore,trustStore=file:///opt/shibboleth-idp/jetty-base/etc/keystore</a>]<br>
2020-09-07 12:44:34.167:<a class="moz-txt-link-freetext"
href="INFO:oejus.SslContextFactory:main"
moz-do-not-send="true">INFO:oejus.SslContextFactory:main</a>:
x509=X509@9aa9e4a(mykey,h=[],w=[]) for
Server@74948d11[provider=null,keyStore=<a
class="moz-txt-link-freetext"
href="file:///opt/shibboleth-idp/jetty-base/etc/keystore,trustStore=file:///opt/shibboleth-idp/jetty-base/etc/keystore"
moz-do-not-send="true">file:///opt/shibboleth-idp/jetty-base/etc/keystore,trustStore=file:///opt/shibboleth-idp/jetty-base/etc/keystore</a>]<br>
2020-09-07 12:44:34.255:<a class="moz-txt-link-freetext"
href="INFO:oejs.AbstractConnector:main" moz-do-not-send="true">INFO:oejs.AbstractConnector:main</a>:
Started ServerConnector@7975d1d8{SSL, (ssl, alpn,
h2)}{0.0.0.0:8443}<br>
2020-09-07 12:44:34.268:<a class="moz-txt-link-freetext"
href="INFO:oejs.AbstractConnector:main" moz-do-not-send="true">INFO:oejs.AbstractConnector:main</a>:
Started ServerConnector@18f8cd79{HTTP/1.1, (http/1.1,
h2c)}{0.0.0.0:8080}<br>
2020-09-07 12:44:34.269:<a class="moz-txt-link-freetext"
href="INFO:oejs.Server:main" moz-do-not-send="true">INFO:oejs.Server:main</a>:
Started @35987ms<br>
2020-09-07
12:44:34.269:WARN:oejuc.FileNoticeLifeCycleListener:main: <br>
java.io.FileNotFoundException:
/opt/shibboleth-idp/jetty-base/jetty.state (Permission denied)<br>
at java.base/java.io.FileOutputStream.open0(Native Method)<br>
at
java.base/java.io.FileOutputStream.open(FileOutputStream.java:298)<br>
at
java.base/java.io.FileOutputStream.<init>(FileOutputStream.java:237)<br>
at
java.base/java.io.FileOutputStream.<init>(FileOutputStream.java:158)<br>
at
java.base/java.io.FileWriter.<init>(FileWriter.java:82)<br>
at
org.eclipse.jetty.util.component.FileNoticeLifeCycleListener.writeState(FileNoticeLifeCycleListener.java:44)<br>
at
org.eclipse.jetty.util.component.FileNoticeLifeCycleListener.lifeCycleStarted(FileNoticeLifeCycleListener.java:63)<br>
at
org.eclipse.jetty.util.component.AbstractLifeCycle.setStarted(AbstractLifeCycle.java:193)<br>
at
org.eclipse.jetty.util.component.AbstractLifeCycle.start(AbstractLifeCycle.java:73)<br>
at
org.eclipse.jetty.xml.XmlConfiguration.lambda$main$1(XmlConfiguration.java:1929)<br>
at
java.base/java.security.AccessController.doPrivileged(Native
Method)<br>
at
org.eclipse.jetty.xml.XmlConfiguration.main(XmlConfiguration.java:1878)<br>
at
java.base/jdk.internal.reflect.NativeMethodAccessorImpl.invoke0(Native
Method)<br>
at
java.base/jdk.internal.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62)<br>
at
java.base/jdk.internal.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)<br>
at
java.base/java.lang.reflect.Method.invoke(Method.java:566)<br>
at org.eclipse.jetty.start.Main.invokeMain(Main.java:218)<br>
at org.eclipse.jetty.start.Main.start(Main.java:491)<br>
at org.eclipse.jetty.start.Main.main(Main.java:77)<br>
<br>
</p>
<p><br>
</p>
<div class="moz-cite-prefix">Le 07/09/2020 à 11:20, Ian Young a
écrit :<br>
</div>
<blockquote type="cite"
cite="mid:18492000-0E8D-4F95-8606-893B0F448BAA@iay.org.uk">
<blockquote type="cite">
<pre class="moz-quote-pre" wrap="">On 2020-09-07, at 09:25, Julien Cochennec <a class="moz-txt-link-rfc2396E" href="mailto:julien.cochennec@ac-orleans-tours.fr" moz-do-not-send="true"><julien.cochennec@ac-orleans-tours.fr></a> wrote:
Hi, Id 'like to test the Docker image for Shibboleth IDP 4.
I'm using this : <a class="moz-txt-link-freetext" href="https://hub.docker.com/r/unicon/shibboleth-idp/dockerfile" moz-do-not-send="true">https://hub.docker.com/r/unicon/shibboleth-idp/dockerfile</a>
</pre>
</blockquote>
<pre class="moz-quote-pre" wrap="">This particular image, from Unicon, doesn't seem to be maintained any more. As you've noted, it is in any case for IdP V3 and not even the most recent version of that.
</pre>
<blockquote type="cite">
<pre class="moz-quote-pre" wrap="">Can I change those values to build an IDP V4 Docker image?
</pre>
</blockquote>
<pre class="moz-quote-pre" wrap="">Perhaps in principle. As Alan says, you need to fix all the prerequisites, not just the IdP version.
Given that this image no longer seems to be maintained, though, it might be easier to start with one of the forks, e.g. the one from csc.fi:
Image: <a class="moz-txt-link-freetext" href="https://hub.docker.com/r/cscfi/shibboleth-idp" moz-do-not-send="true">https://hub.docker.com/r/cscfi/shibboleth-idp</a>
Source: <a class="moz-txt-link-freetext" href="https://github.com/CSCfi/shibboleth-idp-dockerized" moz-do-not-send="true">https://github.com/CSCfi/shibboleth-idp-dockerized</a>
There's also the InCommon TIER image:
<a class="moz-txt-link-freetext" href="https://hub.docker.com/r/tier/shib-idp" moz-do-not-send="true">https://hub.docker.com/r/tier/shib-idp</a>
Read this page for more details:
<a class="moz-txt-link-freetext" href="https://spaces.at.internet2.edu/display/ITAP/InCommon+Trusted+Access+Platform+Release" moz-do-not-send="true">https://spaces.at.internet2.edu/display/ITAP/InCommon+Trusted+Access+Platform+Release</a>
These are actively maintained and kept pretty well up to date.
</pre>
<blockquote type="cite">
<pre class="moz-quote-pre" wrap="">If so, what will I need to do to build a v4 SP from this <a class="moz-txt-link-freetext" href="https://hub.docker.com/r/unicon/shibboleth-sp/dockerfile" moz-do-not-send="true">https://hub.docker.com/r/unicon/shibboleth-sp/dockerfile</a> ?
</pre>
</blockquote>
<pre class="moz-quote-pre" wrap="">Version numbers for the IdP and SP are not connected. The latest version of the SP is 3.1.0; there is no V4 at this time.
-- Ian
</pre>
<br>
<fieldset class="mimeAttachmentHeader"></fieldset>
</blockquote>
<pre class="moz-signature" cols="72">--
Julien Cochennec
Pôle de compétences - gestion des identités
Mél <a class="moz-txt-link-abbreviated" href="mailto:julien.cochennec@ac-orleans-tours.fr" moz-do-not-send="true">julien.cochennec@ac-orleans-tours.fr</a>
Tél 02 38 83 48 88
DSI - Rectorat d'Orléans-Tours
10 Rue Molière
45000 Orléans
<a class="moz-txt-link-abbreviated" href="http://www.ac-orleans-tours.fr" moz-do-not-send="true">www.ac-orleans-tours.fr</a></pre>
<br>
<fieldset class="mimeAttachmentHeader"></fieldset>
</blockquote>
<pre class="moz-signature" cols="72">--
Julien Cochennec
Pôle de compétences - gestion des identités
Mél <a class="moz-txt-link-abbreviated" href="mailto:julien.cochennec@ac-orleans-tours.fr">julien.cochennec@ac-orleans-tours.fr</a>
Tél 02 38 83 48 88
DSI - Rectorat d'Orléans-Tours
10 Rue Molière
45000 Orléans
<a class="moz-txt-link-abbreviated" href="http://www.ac-orleans-tours.fr">www.ac-orleans-tours.fr</a></pre>
</body>
</html>