idp-access.log in v3 IdP?

Alex Stuart alex.stuart at ed.ac.uk
Thu Oct 29 07:38:49 EDT 2015



On 28/10/2015 17:14, Cantor, Scott wrote:
> On 10/28/15, 12:51 PM, "users on behalf of Alex Stuart" <users-bounces at shibboleth.net on behalf of alex.stuart at ed.ac.uk> wrote:
> 
>> I've found Shibboleth-Access log messages
>> at INFO useful for debugging while working on the UK federation
>> helpdesk, as it's a clear indication that the IdP has received a HTTP
>> request. We often don't have much to go on.
> 
> A web access log provides that.

Sure, but we often have difficulty getting our users to find the correct
part of an idp-process.log, never mind correlate that with a web access
log. Log messages like:

2015-10-29 11:11:41,076 - DEBUG
[org.opensaml.saml.saml2.binding.decoding.impl.HTTPRedirectDeflateDecoder:64]
- Decoded RelayState: cookie:1446117095_9058

or

2015-10-29 11:27:58,903 - DEBUG
[net.shibboleth.idp.saml.profile.impl.BaseIdPInitiatedSSORequestMessageDecoder:68]
- Beginning to decode message from HttpServletRequest

just seem an inauspicious way to announce the start of user interaction.
I have to get used to this kind of thing; sorry for the gripe.

> 
>> I'm not sure how to add these loglines back in to the process log.
> 
> Doesn't exist.

Fair enough.

Thanks,
Alex

-- 
Alex Stuart
Team Leader - Federated Access Management
EDINA, University of Edinburgh

The University of Edinburgh is a charitable body, registered in
Scotland, with registration number SC005336.



More information about the users mailing list