Shibboleth IdP fails to download metadata then never tries again

Alan Buxey alan.buxey at myunidays.com
Wed Aug 16 18:03:32 EDT 2017


Sure your config doesn't have strange character in it , eg from a cut and
paste operation... Safari, for example, can do horrible things like that
when cutting and pasting from web pages.  We ran a moonshot course in the
surfnet offices a couple of years back and browser cut and paste caused a
couple of issues

alan

On 16 Aug 2017 5:42 pm, <shibboleth655 at lewenberg.com> wrote:

>
>
> On 8/11/2017 10:58 AM, Brian Moon wrote:
>
>> Not sure why it never tries again, but the URL for that metadata should
>> be https://idp.stanford.edu/Stanford-idps.xml (unless you had
>> intentionally appended characters to it to force it to fail to prove that
>> the refresh was not working).
>>
>
> Those extra characters were from the log message whose complete text is
>
> [org.opensaml.saml.metadata.resolver.impl.AbstractReloadingMetadataResolver:294]
> - Metadata Resolver FileBackedHTTPMetadataResolver spdb-metadata-legacy:
> Error occurred while attempting to refresh metadata from '
> https://spdb.stanford.edu/spmetadata/metadata-legacy.xml'
>
>
> I guess the logger converted the single quote to as entity name.
>
>
>
>>
>> Brian Moon
>> Senior System Administrator, Enterprise Systems
>> Elections & Bylaws Committee Co-Chair, Staff Senate 2017-2018
>> Santa Clara University
>> bmoon at scu.edu <mailto:bmoon at scu.edu> | (408) 554-4830 <tel:4085544830>
>>
>> On Fri, Aug 11, 2017 at 10:46 AM, <shibboleth655 at lewenberg.com <mailto:
>> shibboleth655 at lewenberg.com>> wrote:
>>
>>     We are seeing an odd problem with downloading metadata.
>>
>>     Here is the sequence of events.
>>
>>     1. The Shibboleth IdP service has trouble downloading the metadata
>>     at the URL "https://idp.stanford.edu/Stanford-idps.xml&#39
>>     <https://idp.stanford.edu/Stanford-idps.xml&#39>;".
>>
>>     2. It then promises to try again in about 22 minutes.
>>
>>     3. However, there is *never* again a log entry indicating that
>>     Shibboleth IdP attempted to download the metadata at that URL. It is
>>     as if the IdP service stops trying.
>>
>>     4. This is a big problem as now our metadata is getting more and
>>     more stale.
>>
>>
>>     Here are the relevant logs below:
>>
>>     2017-07-27 11:50:00,314 - INFO [org.opensaml.saml.metadata.re
>>     <http://org.opensaml.saml.metadata.re>solver.impl.AbstractRe
>> loadingMetadataResolver:465]
>>     - Metadata Resolver FileBackedHTTPMetadataResolver stanford-idps:
>>     New metadata successfully loaded for
>>     'https://idp.stanford.edu/Stanford-idps.xml&#39
>>     <https://idp.stanford.edu/Stanford-idps.xml&#39>;
>>     2017-07-27 11:50:00,314 - INFO [org.opensaml.saml.metadata.re
>>     <http://org.opensaml.saml.metadata.re>solver.impl.AbstractRe
>> loadingMetadataResolver:306]
>>     - Metadata Resolver FileBackedHTTPMetadataResolver stanford-idps:
>>     Next refresh cycle for metadata provider
>>     'https://idp.stanford.edu/Stanford-idps.xml&#39
>>     <https://idp.stanford.edu/Stanford-idps.xml&#39>; will occur on
>>     '2017-07-27T19:12:30.272Z' ('2017-07-27T12:12:30.272-07:00' local
>> time)
>>     2017-07-27 12:21:35,186 - ERROR [org.opensaml.saml.metadata.re
>>     <http://org.opensaml.saml.metadata.re>solver.impl.HTTPMetada
>> taResolver:313]
>>     - Metadata Resolver FileBackedHTTPMetadataResolver stanford-idps:
>>     Error retrieving metadata from
>>     https://idp.stanford.edu/Stanford-idps.xml
>>     <https://idp.stanford.edu/Stanford-idps.xml>
>>     2017-07-27 12:21:35,194 - INFO [org.opensaml.saml.metadata.re
>>     <http://org.opensaml.saml.metadata.re>solver.impl.AbstractRe
>> loadingMetadataResolver:306]
>>     - Metadata Resolver FileBackedHTTPMetadataResolver stanford-idps:
>>     Next refresh cycle for metadata provider
>>     'https://idp.stanford.edu/Stanford-idps.xml&#39
>>     <https://idp.stanford.edu/Stanford-idps.xml&#39>; will occur on
>>     '2017-07-27T19:37:24.448Z' ('2017-07-27T12:37:24.448-07:00' local
>> time)
>>
>>     (After this point, there is NEVER again a mention of
>>     https://idp.stanford.edu/Stanford-idps.xml&#39
>>     <https://idp.stanford.edu/Stanford-idps.xml&#39> in any of the logs.)
>>
>>
>>     We are running Shibboleth IdP version 3.3.1 with tomcat8 on a Debian
>>     server.
>>
>>
>>     --     To unsubscribe from this list send an email to
>>     users-unsubscribe at shibboleth.net
>>     <mailto:users-unsubscribe at shibboleth.net>
>>
>>
>>
>>
>>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170816/0b42daf3/attachment-0001.html>


More information about the users mailing list