Unknown or Unusable Identity Provider for Shib 3.2 SP

Cantor, Scott cantor.2 at osu.edu
Wed Jun 5 16:17:33 UTC 2024


Back to users...

> However, I don't think that this change is the cause of the
> issues that we're seeing on the SP side, since at this point,
> it appears that the request is never even made to the IdP for
> metadata

Given the limited evidence, my conclusion would be that your belief of that is suspect. Perhaps the upgrade also impacted the access logging required to make that determination.

I would agree that given the same metadata locally, it would not throw that error, it would make the request to the original locations, presuming the entityID was the same as before, and if anything would fail on the response.

When people swear to things I know cannot be true, I do not spend a lot of my time trying to work out how it's true. For this to happen, it would have to be fetching the new metadata and not finding a correlation between the entityIDs. So I am comfortable betting a reasonable sum on that.

A lack of logging doesn't prove anything but a problem with logging unless one had access to the SP's logs. Which is where we came in.

Whatever the cause, it is not possible for somebody to debug this from outside the impacted system.

Were it me, as an IdP operator, I'd revert the entityID in the metadata before I spent a lot of time guessing about it.

-- Scott




More information about the users mailing list