Shibboleth IdP fails to download metadata then never tries again
Alan Buxey
alan.buxey at myunidays.com
Wed Aug 16 18:03:32 EDT 2017
Sure your config doesn't have strange character in it , eg from a cut and
paste operation... Safari, for example, can do horrible things like that
when cutting and pasting from web pages. We ran a moonshot course in the
surfnet offices a couple of years back and browser cut and paste caused a
couple of issues
alan
On 16 Aug 2017 5:42 pm, <shibboleth655 at lewenberg.com> wrote:
>
>
> On 8/11/2017 10:58 AM, Brian Moon wrote:
>
>> Not sure why it never tries again, but the URL for that metadata should
>> be https://idp.stanford.edu/Stanford-idps.xml (unless you had
>> intentionally appended characters to it to force it to fail to prove that
>> the refresh was not working).
>>
>
> Those extra characters were from the log message whose complete text is
>
> [org.opensaml.saml.metadata.resolver.impl.AbstractReloadingMetadataResolver:294]
> - Metadata Resolver FileBackedHTTPMetadataResolver spdb-metadata-legacy:
> Error occurred while attempting to refresh metadata from '
> https://spdb.stanford.edu/spmetadata/metadata-legacy.xml'
>
>
> I guess the logger converted the single quote to as entity name.
>
>
>
>>
>> Brian Moon
>> Senior System Administrator, Enterprise Systems
>> Elections & Bylaws Committee Co-Chair, Staff Senate 2017-2018
>> Santa Clara University
>> bmoon at scu.edu <mailto:bmoon at scu.edu> | (408) 554-4830 <tel:4085544830>
>>
>> On Fri, Aug 11, 2017 at 10:46 AM, <shibboleth655 at lewenberg.com <mailto:
>> shibboleth655 at lewenberg.com>> wrote:
>>
>> We are seeing an odd problem with downloading metadata.
>>
>> Here is the sequence of events.
>>
>> 1. The Shibboleth IdP service has trouble downloading the metadata
>> at the URL "https://idp.stanford.edu/Stanford-idps.xml'
>> <https://idp.stanford.edu/Stanford-idps.xml'>;".
>>
>> 2. It then promises to try again in about 22 minutes.
>>
>> 3. However, there is *never* again a log entry indicating that
>> Shibboleth IdP attempted to download the metadata at that URL. It is
>> as if the IdP service stops trying.
>>
>> 4. This is a big problem as now our metadata is getting more and
>> more stale.
>>
>>
>> Here are the relevant logs below:
>>
>> 2017-07-27 11:50:00,314 - INFO [org.opensaml.saml.metadata.re
>> <http://org.opensaml.saml.metadata.re>solver.impl.AbstractRe
>> loadingMetadataResolver:465]
>> - Metadata Resolver FileBackedHTTPMetadataResolver stanford-idps:
>> New metadata successfully loaded for
>> 'https://idp.stanford.edu/Stanford-idps.xml'
>> <https://idp.stanford.edu/Stanford-idps.xml'>;
>> 2017-07-27 11:50:00,314 - INFO [org.opensaml.saml.metadata.re
>> <http://org.opensaml.saml.metadata.re>solver.impl.AbstractRe
>> loadingMetadataResolver:306]
>> - Metadata Resolver FileBackedHTTPMetadataResolver stanford-idps:
>> Next refresh cycle for metadata provider
>> 'https://idp.stanford.edu/Stanford-idps.xml'
>> <https://idp.stanford.edu/Stanford-idps.xml'>; will occur on
>> '2017-07-27T19:12:30.272Z' ('2017-07-27T12:12:30.272-07:00' local
>> time)
>> 2017-07-27 12:21:35,186 - ERROR [org.opensaml.saml.metadata.re
>> <http://org.opensaml.saml.metadata.re>solver.impl.HTTPMetada
>> taResolver:313]
>> - Metadata Resolver FileBackedHTTPMetadataResolver stanford-idps:
>> Error retrieving metadata from
>> https://idp.stanford.edu/Stanford-idps.xml
>> <https://idp.stanford.edu/Stanford-idps.xml>
>> 2017-07-27 12:21:35,194 - INFO [org.opensaml.saml.metadata.re
>> <http://org.opensaml.saml.metadata.re>solver.impl.AbstractRe
>> loadingMetadataResolver:306]
>> - Metadata Resolver FileBackedHTTPMetadataResolver stanford-idps:
>> Next refresh cycle for metadata provider
>> 'https://idp.stanford.edu/Stanford-idps.xml'
>> <https://idp.stanford.edu/Stanford-idps.xml'>; will occur on
>> '2017-07-27T19:37:24.448Z' ('2017-07-27T12:37:24.448-07:00' local
>> time)
>>
>> (After this point, there is NEVER again a mention of
>> https://idp.stanford.edu/Stanford-idps.xml'
>> <https://idp.stanford.edu/Stanford-idps.xml'> in any of the logs.)
>>
>>
>> We are running Shibboleth IdP version 3.3.1 with tomcat8 on a Debian
>> server.
>>
>>
>> -- To unsubscribe from this list send an email to
>> users-unsubscribe at shibboleth.net
>> <mailto:users-unsubscribe at shibboleth.net>
>>
>>
>>
>>
>>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170816/0b42daf3/attachment-0001.html>
More information about the users
mailing list