IdP 3.3.1 - mac check in GCM failed

Cantor, Scott cantor.2 at osu.edu
Tue Jun 13 09:30:54 EDT 2017


On 6/13/17, 8:30 AM, "users on behalf of George Stoynev" <users-bounces at shibboleth.net on behalf of george.stoynev at mcgill.ca> wrote:

> Interesting ... I found the following entries in the idp-process.log which may be related:

Not directly, that case is a missing key, and that's normal, people come back days later with stale data encrypted under an older key that rolled off. All of that is tuneable, but decrypting an expired session doesn't really do anything useful anyway.

> The secret key has been updated on daily basis and pushed from the first server to the second one (two servers in total). Just
> compared the md5sums on both nodes - they match. Rerun the cron job manually and copied the files over manually as well - no
> errors, still md5sums match. The error messages persist. 

I scanned my logs, there's no sign of that error, so I have no reason to doubt my diagnosis.

If the problem had something to do with the crypto policy files in the JDK it would prevent a node from ever working. I suppose if every single decryption attempt is failing, that would fit.

Otherwise, my next question would be the usual, is this OpenJDK? If it is, switch.

-- Scott




More information about the users mailing list