Shibboleth IdP gives 503 after upgrade to IdP 5 and Jetty 11

Waddell, Michael (waddelml) waddelml at ucmail.uc.edu
Tue Feb 13 14:26:45 UTC 2024


We are running Shibboleth 4.3.1, using Jetty 10.0.15 and Java 17 (with Nashorn) on a Redhat 8.9 server, and we are attempting to upgrade the IdP and Jetty. Before the update it works fine with no deprecation warnings.

Following the instructions on https://shibboleth.atlassian.net/wiki/spaces/IDP5/pages/3199500925/Upgrading, I removed the system directory, and everything continued to work fine. I stopped Jetty and backed everything up, and then I upgraded in-place by installing shibboleth-identity-provider-5.0.0. Then I upgraded Jetty to jetty-home-11.0.20. I started Jetty up, and it seemed to come up fine. The Shibboleth logs show what I would expect when everything comes up correctly ("RemoteUserAuthServlet will process REMOTE_USER, along with attributes [] and headers []"). But when I look at servername/idp/status (or any other Shibboleth URL), I get a 503.

     URI: /idp/status
     STATUS: 503
     MESSAGE: Service Unavailable
     SERVLET: -
     Powered by Jetty:// 11.0.20

There are no errors in the Shibboleth logs, and Jetty claims to be running fine. I can't figure out why it's not recognizing Shibboleth. When I restore the /opt/jetty and /opt/shibboleth-idp directories from my backups of the previous versions, everything works again. Has anyone had this experience, and does anyone know what I might try or where I might look?

All the best,

Michael Waddell
Digital Technology Solutions
University of Cincinnati
he/him/his

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20240213/9629d77d/attachment.htm>


More information about the users mailing list