Authentication issue after upgrading to shibboleth-2.5.0-2.1 service provider software

Cantor, Scott cantor.2 at osu.edu
Thu Aug 30 20:12:17 EDT 2012


On 8/30/12 5:53 PM, "Terry Smith" <t.smith at aaf.edu.au> wrote:
>
>      Files to look at will include the local copy of the federation
>metadata file defined in the backingFilePath of the MetadataProvider and
>any certificates keys that are defined in the CredentialResolver, eg
>sp-key.pem. Check the ownership and protection
> of these files to see if the shibd user can read and or write these
>files.

Any private key not named by default in particular, yes.

Unless you specify the backing file(s) for metadata using an absolute
path, that shouldn't cause any problem. The default backup location
changed, so permissions on old files won't matter, and the init script for
shibd already chowns the old /var/run files.

But I assumed there were no warnings in the log, based on the OP's message.

-- Scott



More information about the users mailing list