Errors after Relying Party Service Reload
Christopher Bongaarts
cab at umn.edu
Mon Apr 2 21:15:53 BST 2012
On 4/2/2012 3:02 PM, Slaughter, Brett wrote:
> We’ve configured IdP v2.3.6 on RHEL6 x64 to reload the attribute filter
> engine, attribute resolver, and relying party configuration manager
> services every 2 hours in service.xml. The IdP starts normally and runs
> fine, however the IdP starts throwing errors after the relying party
> configuration manager reloads following a manual change to
> relying-party.xml even though the affected SPs were accessed
> successfully prior to the reload. These issues are resolved after
> restarting Tomcat. The SPs involved in the error’d transactions differ
> after each Tomcat restart/relying-party update. The specific errors
> encountered on the IdP are pasted below, and result in a
> FatalProfileException with message “Unable to encrypt assertion” on the SP.
FWIW, we have also seen this behavior (in essentially the same SW/HW
configuration, and also on IdP 2.1.3 on Solaris). We hadn't had the
time yet to research whether it was just us or a bug.
We don't see this problem with attribute-filter.xml. My memory is hazy
but I think we did see this problem or something similar when reloading
attribute-resolver.xml.
Our workaround has been to restart the container when changing the
relying-party file (avoiding downtime via load balancer).
--
%% Christopher A. Bongaarts %% cab at umn.edu %%
%% OIT - Identity Management %% http://umn.edu/~cab %%
%% University of Minnesota %% +1 (612) 625-1809 %%
More information about the users
mailing list