Unknown or Unusable Identity Provider

Cantor, Scott cantor.2 at osu.edu
Tue Dec 3 14:06:10 EST 2019


On 12/3/19, 1:56 PM, "users on behalf of Conroy Baltzell" <users-bounces at shibboleth.net on behalf of baltzell at umich.edu> wrote:

>  How would I tell if it was an expired validUntil? 

You're misunderstanding the point if you're imagining the source is the proble,. The metadata is expired, and you can see that in the cached copy in /var/cache/shibbleth. Your logs have been logging the libcurl error for an indeterminate amount of time. The metadata is expired because the server began failing to refresh its copy of the metadata and once the metadata expired, the other error appeared.

The point at which the corruption occurred is the point at which shibd was restarted after improper removal of the files installed by the RPM package, and it would have begun logging the actual error leading to the metadata expiring at that point.

-- Scott




More information about the users mailing list