Upped memory guidance
Tim McLaughlin
Tim.McLaughlin at wwu.edu
Mon Feb 22 16:30:12 EST 2016
I should mention that I had already increased the heap size for Shibboleth to 2G, so I think I'm set for the directives in the email.
Tim
On 16-02-22, 13:16, "users on behalf of Tim McLaughlin" <users-bounces at shibboleth.net on behalf of Tim.McLaughlin at wwu.edu> wrote:
>This is regarding Shibboleth IdP 2.4.3.
>
>I received the [ACTION REQUIRED] email mentioned below, and have done the inspection and Logging.xml config change.
>I can see that the metadata refresh process succeeds for the InCommon-metadata source.
>
>One question about the two-week validity period, just to be thorough: Is it two weeks from the "creationInstant" value? One of the lines in the DEBUG output implies that it will expire about an hour from when I restarted my (backup) Shibboleth server. I've included all of the relevant log lines, but the one that has me concerned is the last DEBUG line:
>
>12:59:16.890 - DEBUG [org.opensaml.saml2.metadata.provider.AbstractReloadingMetadataProvider:253] - Beginning refresh of metadata from 'http://md.incommon.org/InCommon/InCommon-metadata.xml'
>13:01:47.351 - DEBUG [org.opensaml.saml2.metadata.provider.AbstractReloadingMetadataProvider:260] - Processing new metadata from 'http://md.incommon.org/InCommon/InCommon-metadata.xml'
>13:01:47.352 - DEBUG [org.opensaml.saml2.metadata.provider.AbstractReloadingMetadataProvider:349] - Unmarshalling metadata from 'http://md.incommon.org/InCommon/InCommon-metadata.xml'
>13:01:50.383 - DEBUG [org.opensaml.saml2.metadata.provider.AbstractReloadingMetadataProvider:393] - Filtering metadata from 'http://md.incommon.org/InCommon/InCommon-metadata.xml'
>13:01:51.516 - DEBUG [org.opensaml.saml2.metadata.provider.AbstractReloadingMetadataProvider:402] - Releasing cached DOM for metadata from 'http://md.incommon.org/InCommon/InCommon-metadata.xml'
>13:01:51.598 - DEBUG [org.opensaml.saml2.metadata.provider.AbstractReloadingMetadataProvider:405] - Post-processing metadata from 'http://md.incommon.org/InCommon/InCommon-metadata.xml'
>13:01:51.640 - DEBUG [org.opensaml.saml2.metadata.provider.AbstractReloadingMetadataProvider:408] - Computing expiration time for metadata from 'http://md.incommon.org/InCommon/InCommon-metadata.xml'
>13:01:51.712 - DEBUG [org.opensaml.saml2.metadata.provider.AbstractReloadingMetadataProvider:411] - Expiration of metadata from 'http://md.incommon.org/InCommon/InCommon-metadata.xml' will occur at 2016-02-22T21:59:16.890Z
>13:01:51.713 - INFO [org.opensaml.saml2.metadata.provider.AbstractReloadingMetadataProvider:428] - New metadata succesfully loaded for 'http://md.incommon.org/InCommon/InCommon-metadata.xml'
>13:01:51.713 - INFO [org.opensaml.saml2.metadata.provider.AbstractReloadingMetadataProvider:276] - Next refresh cycle for metadata provider 'http://md.incommon.org/InCommon/InCommon-metadata.xml' will occur on '2016-02-22T21:44:55.595Z' ('2016-02-22T13:44:55.595-08:00' local time)
>
>
>
>
>Is this something to be concerned about or is this just my misunderstanding of the data in the log?
>
>Thanks,
>Tim
>
>
>On 16-02-19, 16:45, "users on behalf of Tom Scavo" <users-bounces at shibboleth.net on behalf of trscavo at gmail.com> wrote:
>
>>On Fri, Feb 19, 2016 at 7:18 PM, Nate Klingenstein <ndk at sudonym.me> wrote:
>>> Do we know what the validUntil time in the last signed edition of eduGAIN-less metadata was? Do we anticipate that being poised on that day may be needed?
>>
>>I assume you're asking about InCommon metadata, in which case this
>>question is more appropriate for an InCommon mailing list, but yes, we
>>are messaging InCommon Federation Site Administrators on Monday, which
>>is halfway through the two-week validity period for InCommon metadata.
>>The timing is not accidental. I suspect some Shib IdP software has
>>quietly died (because of a logging bug) and so we will suggest that
>>deployers inspect the backing file to make sure there is no smoking
>>gun.
>>
>>Tom
>>--
>>To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
>--
>To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list