idp logging to syslog retains stack trace when it shouldn't
Don Faulkner
donf at uark.edu
Fri Jun 1 03:46:57 BST 2012
Just wanted to close the loop on this one. My filed bug[1] with LogBack was addressed in the latest 1.0.4 release out today. Hopefully that can be included in an upcoming release of the IdP, but I'm going to give it a drop-in try in my dev environment. According to the updated SyslogAppender Docs[2], there's a new property called throwableExcluded:
Setting throwableExcluded to true will cause stack trace data associated with a Throwable to be omitted. By default,throwableExcluded is set to false so that stack trace data is sent to the syslog server.
Cheers!
[1] http://jira.qos.ch/browse/LBCLASSIC-327
[2] http://logback.qos.ch/manual/appenders.html#SyslogAppender
--
[me]
Don Faulkner, CISSP | IT Security<http://its.uark.edu/> at the University of Arkansas<http://www.uark.edu/>
contact>> donf at uark.edu<mailto:donf at uark.edu> | +1 (479) 575-2905
connect>> uarkITS on Facebook<http://www.facebook.com/uarkITS> | @uaits<http://twitter.com/uaits> | @dfaulkner<http://twitter.com/dfaulkner>
On Apr 20, 2012, at 2:30 PM, Don Faulkner wrote:
On 04/18/2012 05:10 PM, Chad La Joie wrote:
Yes that's where you'll need to ask. We have no control over that library.
On Wed, Apr 18, 2012 at 17:59, Don Faulkner <donf at uark.edu><mailto:donf at uark.edu> wrote:
I'm going to ask a similar question over at the logback project, too.
Unfortunately, they're not very responsive. I'll give it a few days. My temporary workaround is some pretty aggressive filtering at the syslog layer.
What's the general consensus on audit logging from the IdP or SP?
--
[me] Don Faulkner, CISSP | IT Security<http://its.uark.edu/> at the University of Arkansas<http://www.uark.edu/>
contact>> donf at uark.edu<mailto:donf at uark.edu> | +1 (479) 575-2905
connect>> uarkITS on Facebook<http://www.facebook.com/uarkITS> | @uaits<http://twitter.com/uaits> | @dfaulkner<http://twitter.com/dfaulkner>
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net<mailto:users-unsubscribe at shibboleth.net>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20120601/e2ab9340/attachment.html
More information about the users
mailing list