Unknown or Unusable Identity Provider for Shib 3.2 SP
Cantor, Scott
cantor.2 at osu.edu
Wed Jun 5 16:17:33 UTC 2024
Back to users...
> However, I don't think that this change is the cause of the
> issues that we're seeing on the SP side, since at this point,
> it appears that the request is never even made to the IdP for
> metadata
Given the limited evidence, my conclusion would be that your belief of that is suspect. Perhaps the upgrade also impacted the access logging required to make that determination.
I would agree that given the same metadata locally, it would not throw that error, it would make the request to the original locations, presuming the entityID was the same as before, and if anything would fail on the response.
When people swear to things I know cannot be true, I do not spend a lot of my time trying to work out how it's true. For this to happen, it would have to be fetching the new metadata and not finding a correlation between the entityIDs. So I am comfortable betting a reasonable sum on that.
A lack of logging doesn't prove anything but a problem with logging unless one had access to the SP's logs. Which is where we came in.
Whatever the cause, it is not possible for somebody to debug this from outside the impacted system.
Were it me, as an IdP operator, I'd revert the entityID in the metadata before I spent a lot of time guessing about it.
-- Scott
More information about the users
mailing list