Trying to set up Shibboleth IDP 5 but get no logging output

Pete Birkinshaw pete at digitalidentitylabs.com
Fri Jan 12 18:14:51 UTC 2024


Hi,

Have you checked if it's SystemD sandboxing? SystemD may be restricting where Tomcat can write. If so, you can use ReadWritePaths in the unit file (or unit file override) to give systemD permission to write to the logs directory.


Pete 

-- 
Pete Birkinshaw
Digital Identity Ltd | http://www.digitalidentity.ltd.uk 
Registered in England and Wales No. 7121888 

From: Fin, Silvan Marco via users <users at shibboleth.net>
Reply: Shib Users <users at shibboleth.net>
Date: 12 January 2024 at 15:12:16
To: users at shibboleth.net <users at shibboleth.net>
Cc: Fin, Silvan Marco <silvan.fin at uni-siegen.de>
Subject:  Trying to set up Shibboleth IDP 5 but get no logging output

Hi,

 

I'm using a Shibboleth IDP v4.0.X (and older versions of the IDP before that) and am interested in trying out version 5.0.0.

 

So I grabbed a VM, read the installation requirements, setup the environment as described, and now I’m stuck with no log files, which makes the handling of “is it doing anything at all?” really hard.

 

Here is my setup:

HW: x64 VM

OS: Ubuntu 23.10 (fresh install)

Java: AWS Corretto 17 java-17-amazon-corretto-jdk:amd64

Servlet Engine: tomcat10 as supplied by ubuntu 23.10

 

The IDP is running according to tomcat log. I’m getting some IDP page when browsing the /idp/-url and tomcat manager app lists the IDP as deployed and running.

 

I was expecting something similar to what has happened in the past, where IDP logging was directed to ${idp.home}/logs, specifically idp-process.log. I’ve tried different approaches, reread the installation instructions, retraced my steps and yet… the directory remains empty. I'm sure I'm missing something, but I haven't figured out what it might be yet. Perhaps some java module is missing or a setting in a properties file or some xml configuration.

 

I would be very happy to hear whether anyone has had similar experiences and whether and how the problems could be solved.

 

Kind regards

Silvan Fin

--  
For Consortium Member technical support, see https://shibboleth.atlassian.net/wiki/x/ZYEpPw  
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20240112/5c62e5c2/attachment.htm>


More information about the users mailing list