InCommon metadata problem now fixed - how to detect in the future

Wessel, Keith kwessel at illinois.edu
Wed Feb 25 15:50:34 EST 2015


And if you want something external to the IDP, you could certainly use a Nagios probe or a simple script to check the last modify date on the InCommon metadata file on your server. If it's more than a few days old without being modified, chances are something broke. Checking for specific errors downloading metadata as Scott suggested is still the better way to go, but a second safety net can't hurt.

Keith


-----Original Message-----
From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] On Behalf Of Cantor, Scott
Sent: Wednesday, February 25, 2015 2:47 PM
To: Shib Users
Subject: Re: InCommon metadata problem now fixed - how to detect in the future

On 2/25/15, 8:34 PM, "Tom Scavo" <trscavo at gmail.com> wrote:


>
>which is what it should be doing but exactly two weeks ago we
>introduced the MD-RPI schema into production metadata and I'll bet
>that broke your metadata refresh process somehow. Something you did
>today must have brought it back to life.

I can't think how.

Usually when people have problems, it's due to misguided security people 
trying to use outbound firewall rules.

> Is there anything I can do to be alerted to this kind of thing?
> I suppose I could have a script grep through the log file every 5 minutes
> for new errors and send me an email when they're found.
> But is there something more elegant?

logback has plenty of capabilities for routing errors in different ways, 
filtering on messages, using appenders to email people, etc.

-- Scott

-- 
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list