Errors after Relying Party Service Reload

Christopher Bongaarts cab at umn.edu
Mon Apr 2 21:15:53 BST 2012


On 4/2/2012 3:02 PM, Slaughter, Brett wrote:
> We’ve configured IdP v2.3.6 on RHEL6 x64 to reload the attribute filter
> engine, attribute resolver, and relying party configuration manager
> services every 2 hours in service.xml. The IdP starts normally and runs
> fine, however the IdP starts throwing errors after the relying party
> configuration manager reloads following a manual change to
> relying-party.xml even though the affected SPs were accessed
> successfully prior to the reload. These issues are resolved after
> restarting Tomcat. The SPs involved in the error’d transactions differ
> after each Tomcat restart/relying-party update. The specific errors
> encountered on the IdP are pasted below, and result in a
> FatalProfileException with message “Unable to encrypt assertion” on the SP.

FWIW, we have also seen this behavior (in essentially the same SW/HW 
configuration, and also on IdP 2.1.3 on Solaris).  We hadn't had the 
time yet to research whether it was just us or a bug.

We don't see this problem with attribute-filter.xml.  My memory is hazy 
but I think we did see this problem or something similar when reloading 
attribute-resolver.xml.

Our workaround has been to restart the container when changing the 
relying-party file (avoiding downtime via load balancer).
-- 
%%  Christopher A. Bongaarts   %%  cab at umn.edu          %%
%%  OIT - Identity Management  %%  http://umn.edu/~cab  %%
%%  University of Minnesota    %%  +1 (612) 625-1809    %%


More information about the users mailing list