AW: Metadata not updating in IDP

RUETZ Alexander alexander.ruetz at tirol.gv.at
Thu Feb 19 06:57:48 EST 2015


On 3 Oct 2014, at 15:06, Matthew Slowe <M.Slowe at kent.ac.uk> wrote:
>> 
>> On Fri, Oct 03, 2014 at 10:27:24AM +0100, Rod Widdowson wrote:
>>> Does this look familiar?
>>> 
>>> https://issues.shibboleth.net/jira/browse/JOST-220
>>> 
>>> TL;DR we spotted a potential bug in OpenSAML and fixed it.  We don't know if
>>> this is the cause because we never reproduced the problem.  This potential
>>> fix is available in 2.4.2.  Also you might want to check your container
>>> logs.
>>
>> The "java.lang.IllegalArgumentException: Negative delay." in there does
>> -- it's in the tomcat logs.
>> 
>> I will look at getting the IDP upgraded :-)
>
>Upgraded to 2.4.2 some time ago and still seeing this issue. No longer seeing the "Negative delay" error in the container logs though.
>
>18:35:28.934 - DEBUG [org.opensaml.security.MetadataCredentialResolver:167] - Forcing on-demand metadata provider refresh if necessary
>18:35:28.934 - DEBUG [org.opensaml.saml2.metadata.provider.AbstractMetadataProvider:87] - Metadata document exists, but it is no longer valid
>
>Any other ideas?

Hi Matthew,

you could check if the metadata you are trying to fetch has an already expired validUntil set.

Alex


More information about the users mailing list