InCommon metadata problem now fixed - how to detect in the future

Clayton upnyhgb8v6 at snkmail.com
Wed Feb 25 14:22:59 EST 2015


Hi everyone,

I work at a university and we run a Shib IDP to provide SSO to our users
as they use an ever increasing number of off campus hosted web sites.

This morning I got a call from our Help Desk telling me that there were
Shib SSO errors.  Eventually I figured out that the problem was only with
the SPs which are part of the InCommon federation.  About the time I was
coming to this conclusion and finding that I was having a difficult time
downloading the HTTP-file-backed metadata file from InCommon, the problem
cleared up.  I think they fixed it on their end (by switching to a "fall
back" server or file).

Specifically we started seeing symptoms b/c of this first line in the
InCommon metadata file:

	<Entitiesdescriptor ...  validuntil="2015-02-25t10:00:00z" ...

The error has been in the log file for a while:
	Error [org.Opensaml.Saml2.Metadata.Provider.Httpmetadataprovider:262] -
error retrieving metadata from ...

Is there anything I can do to be alerted to this kind of thing?
I suppose I could have a script grep through the log file every 5 minutes
for new errors and send me an email when they're found.
But is there something more elegant?
FWIW, this is currently on a Windows server.  If there are some nice
additional tools we could use on another OS, I'm open to hearing about
them.

--Clayton

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20150225/61c09a39/attachment.html 


More information about the users mailing list