App pool crash / filter unloaded - ShibSP 2.5.1 on Windows 2008 Server SP2

Adam Cohen adamcohen at berkeley.edu
Mon Mar 4 12:58:47 EST 2013


Definitely getting output in native.log, e.g:
2013-03-04 09:43:08 INFO XMLTooling.Config : xmltooling 1.5.2 library initialization complete
2013-03-04 09:43:08 INFO Shibboleth.Config : shibboleth 2.5.1 library initialization complete
2013-03-04 09:43:08 INFO Shibboleth.Config : reload thread started...running when signaled
2013-03-04 09:43:08 INFO Shibboleth.Config : loaded XML resource (C:/opt/shibboleth-sp/etc/shibboleth/shibboleth2.xml)
2013-03-04 09:43:08 INFO Shibboleth.Config : Shibboleth SP Version 2.5.1
2013-03-04 09:43:08 INFO Shibboleth.Config : Library versions: log4shib 1.0.5, Xerces-C 3.1.1, XMLTooling-C 1.5.2, Shibboleth 1.5.1
2013-03-04 09:43:08 INFO Shibboleth.Config : building ListenerService of type TCPListener...
2013-03-04 09:43:08 INFO Shibboleth.Config : no SessionCache specified, using StorageService-backed instance
2013-03-04 09:43:08 INFO Shibboleth.Config : building RequestMapper of type Native...
2013-03-04 09:43:08 INFO Shibboleth.Config : building ProtocolProvider of type XML...
2013-03-04 09:43:08 INFO Shibboleth.SessionCache : cleanup thread started...run every 900 secs; timeout after 900 secs
2013-03-04 09:43:08 INFO Shibboleth.ProtocolProvider.XML : loaded XML resource (C:/opt/shibboleth-sp/etc/shibboleth/protocols.xml)
2013-03-04 09:43:08 INFO Shibboleth.Application : auto-configuring SSO initiation for protocol (SAML2)
2013-03-04 09:43:08 INFO Shibboleth.Application : adding SessionInitiator of type (SAML2) to chain (/Login)
2013-03-04 09:43:08 INFO Shibboleth.Application : auto-configuring ArtifactResolution endpoints for protocol (SAML2)
2013-03-04 09:43:08 INFO Shibboleth.Application : adding ArtifactResolutionService for Binding (urn:oasis:names:tc:SAML:2.0:bindings:SOAP) at (/Artifact/SOAP)
2013-03-04 09:43:08 INFO Shibboleth.Application : auto-configuring SSO endpoints for protocol (SAML2)
2013-03-04 09:43:08 INFO Shibboleth.Application : adding AssertionConsumerService for Binding (urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST) at (/SAML2/POST)
2013-03-04 09:43:08 INFO Shibboleth.Application : adding AssertionConsumerService for Binding (urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign) at (/SAML2/POST-SimpleSign)
2013-03-04 09:43:08 INFO Shibboleth.Application : adding AssertionConsumerService for Binding (urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact) at (/SAML2/Artifact)
2013-03-04 09:43:08 INFO Shibboleth.Application : adding AssertionConsumerService for Binding (urn:oasis:names:tc:SAML:2.0:bindings:PAOS) at (/SAML2/ECP)
2013-03-04 09:43:08 INFO Shibboleth.Application : auto-configuring SSO initiation for protocol (SAML1)
2013-03-04 09:43:08 INFO Shibboleth.Application : adding SessionInitiator of type (Shib1) to chain (/Login)
2013-03-04 09:43:08 INFO Shibboleth.Application : auto-configuring SSO endpoints for protocol (SAML1)
2013-03-04 09:43:08 INFO Shibboleth.Application : adding AssertionConsumerService for Binding (urn:oasis:names:tc:SAML:1.0:profiles:browser-post) at (/SAML/POST)
2013-03-04 09:43:08 INFO Shibboleth.Application : adding AssertionConsumerService for Binding (urn:oasis:names:tc:SAML:1.0:profiles:artifact-01) at (/SAML/Artifact)
2013-03-04 09:43:08 INFO Shibboleth.Application : adding SessionInitiator of type (SAMLDS) to chain (/Login)
2013-03-04 09:43:08 INFO Shibboleth.Application : auto-configuring Logout initiation for protocol (SAML2)
2013-03-04 09:43:08 INFO Shibboleth.Application : adding LogoutInitiator of type (SAML2) to chain (/Logout)
2013-03-04 09:43:08 INFO Shibboleth.Application : auto-configuring Logout endpoints for protocol (SAML2)
2013-03-04 09:43:08 INFO Shibboleth.Application : adding SingleLogoutService for Binding (urn:oasis:names:tc:SAML:2.0:bindings:SOAP) at (/SLO/SOAP)
2013-03-04 09:43:08 INFO Shibboleth.Application : adding SingleLogoutService for Binding (urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect) at (/SLO/Redirect)
2013-03-04 09:43:08 INFO Shibboleth.Application : adding SingleLogoutService for Binding (urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST) at (/SLO/POST)
2013-03-04 09:43:08 INFO Shibboleth.Application : adding SingleLogoutService for Binding (urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact) at (/SLO/Artifact)
2013-03-04 09:43:08 INFO Shibboleth.Application : auto-configuring Logout initiation for protocol (Local)
2013-03-04 09:43:08 INFO Shibboleth.Application : adding LogoutInitiator of type (Local) to chain (/Logout)
2013-03-04 09:43:08 INFO Shibboleth.DiscoveryFeed : feed files will be cached in C:/opt/shibboleth-sp/var/cache/shibboleth/

Also event viewer is noticing when the app pool is recycled - it's interesting that the sequence of errors is: filter shutdown/w3wp fault/filter initialized 
Information	3/4/2013 9:43:08 AM	Shibboleth ISAPI Filter	7701	Filter initialized...
Error			3/4/2013 9:42:51 AM	Application Error		1000	(100) 	Faulting application w3wp.exe, version 7.0.6002.18005, time stamp 0x49e023cf, faulting module ntdll.dll, version 6.0.6002.18541, time stamp 0x4ec3e39f, exception code 0xc0000374, fault offset 0x000abc4f, process id 0xea4, application start time 0x01ce18d1947db0e3.
Information	3/4/2013 9:42:51 AM	Shibboleth ISAPI Filter	7701	Filter shut down...

Im happy to setup debug and try to capture the stack trace but need a pointer to the procedure.  It seems to be more than just copying the DEBUG version of the DLL into place.  Looks like W3WP.EXE may need to be run with the "-debug" parameter.  I don't have Visual Studio available for runtime debugging.


-- 
Adam Cohen / IT Manager
Energy Biosciences Institute / UC Berkeley
2151 Berkeley Way, Room 212-A / 510-642-7709
http://www.energybiosciencesinstitute.org

On Mar 1, 2013, at 7:26 PM, "Cantor, Scott" <cantor.2 at osu.edu> wrote:

> On 3/1/13 9:51 PM, "Cantor, Scott" <cantor.2 at osu.edu> wrote:
> 
>> There should be a native.log created, and if not, something is clearly
>> wrong with the permissions because that would mean it's not even trying to
>> load.
> 
> Another thing to check for would be event log notices of the filter
> initializing before you see the crash entries (which would be related to
> whether a log file is created or not).
> 
> Also, you mentioned write access, but something lacking read access is a
> more likely crash cause at this point. I think the write failures are
> handled now. I'd check whether the AppPool identity can read all the
> libraries, including the shared stuff in Program Files or Program Files
> x86.
> 
> -- Scott
> 
> 
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net



More information about the users mailing list