v2->v3 upgrade, properties files

Baron Fujimoto baron at hawaii.edu
Wed Jul 6 19:17:19 EDT 2016


On Thu, Jun 23, 2016 at 01:47:14PM +0000, Cantor, Scott wrote:
>> Ok, thanks for the info. Just to make sure I understand correctly, are
>> properties globally accessible as long as they are defined in
>> idp.properties or one of the additional files defined by
>> idp.additionalProperties?
>
>As far as I know.
>
>> This seems consistent with what I guessed might be happening, but given
>> this, I'm still confused by the error we see:
>
>I explained that at the end of my response. The schema uses an enum for a variety of LDAP settings. So there's no way they're going to work with properties. I can only speculate how it worked before.

(finally getting around to following up on this)

Sorry, I missed that on first read, but sort of figured it out along the way
afterwards.

>> So it doesn't complain about the other LDAP properties, but just
>> connectionStrategy?
>
>That's an enum. There are several of them left in the LDAP connector schema. Whether those are bugs or deliberate I couldn't say.

Ok, thanks for the confirmation. I'll certainly have to keep in mind the
potential gotchas re property substitutions.

>> I don't know if it's relevant, but our idp.home isn't /opt/shibboleth-idp
>> but I do have it defined as a JAVA_OPT when starting the IdP.
>
>It's not.

Roger, that.

-- 
Baron Fujimoto <baron at hawaii.edu> :: UH Information Technology Services
minutas cantorum, minutas balorum, minutas carboratum desendus pantorum


More information about the users mailing list