Shibboleth IdP gives 503 after upgrade to IdP 5 and Jetty 11
Waddell, Michael (waddelml)
waddelml at ucmail.uc.edu
Tue Feb 13 14:26:45 UTC 2024
We are running Shibboleth 4.3.1, using Jetty 10.0.15 and Java 17 (with Nashorn) on a Redhat 8.9 server, and we are attempting to upgrade the IdP and Jetty. Before the update it works fine with no deprecation warnings.
Following the instructions on https://shibboleth.atlassian.net/wiki/spaces/IDP5/pages/3199500925/Upgrading, I removed the system directory, and everything continued to work fine. I stopped Jetty and backed everything up, and then I upgraded in-place by installing shibboleth-identity-provider-5.0.0. Then I upgraded Jetty to jetty-home-11.0.20. I started Jetty up, and it seemed to come up fine. The Shibboleth logs show what I would expect when everything comes up correctly ("RemoteUserAuthServlet will process REMOTE_USER, along with attributes [] and headers []"). But when I look at servername/idp/status (or any other Shibboleth URL), I get a 503.
URI: /idp/status
STATUS: 503
MESSAGE: Service Unavailable
SERVLET: -
Powered by Jetty:// 11.0.20
There are no errors in the Shibboleth logs, and Jetty claims to be running fine. I can't figure out why it's not recognizing Shibboleth. When I restore the /opt/jetty and /opt/shibboleth-idp directories from my backups of the previous versions, everything works again. Has anyone had this experience, and does anyone know what I might try or where I might look?
All the best,
Michael Waddell
Digital Technology Solutions
University of Cincinnati
he/him/his
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20240213/9629d77d/attachment.htm>
More information about the users
mailing list