Keep the Shib IdP running if there are some issues in relying-party.xml file
Yaowen Tu
yaowen.tu at gmail.com
Wed Mar 20 16:00:52 EDT 2013
Peter,
I totally agree with you. I was just trying to test some error cases and
see how IdP handles these cases, and seems like it is very reasonable. We
cannot do everything just best effort.
By the way, I have submitted the issue in the bug system.
Yaowen
On Wed, Mar 20, 2013 at 1:18 AM, Peter Schober
<peter.schober at univie.ac.at>wrote:
> * Yaowen Tu <yaowen.tu at gmail.com> [2013-03-20 02:51]:
> > Log says the metadata file has not changed since last refresh.
> >
> > While I am expecting to see an error log says the file doesn't
> > exist.
>
> If that's the case you should report an issue in the bug tracker.
>
> Note that in many year of production we never "lost" local files (in
> your case metadata) and there are plenty of things you can do to
> protect yourself against such cases (e.g. cfengine or tripwire could
> make sure the correct file exists in the correct place with the
> correct content).
> If "missing" local files are generally an issue you'd be in much more
> trouble if any of the files in conf/ or the keystore in credentials/
> were gone -- how would you expect the software to protect you from
> that?
>
> If the issue is defining metadata providers which point to
> non-existing files, well, you've got a broken configuration. I'd make
> sure such a config never goes live on a production server (e.g. by
> having a test instance in place and actually test stuff there).
>
> Its much more likely for remote metadata resources (outside your
> control) to become unavailable, at least temporarily, which you cannot
> influence with local tooling. The IdP handles these cases fine (with
> a plethora of settings you've seen for the metadata provider, to
> influence behaviour).
> -peter
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130320/c30b46ca/attachment.html
More information about the users
mailing list