IdP 5 not accessible after upgrade on a Ubuntu server
Equbay Kiflay
equbay.kiflay at concordia.ab.ca
Wed Jan 22 01:27:15 UTC 2025
Hi Keith,
It has been quite some time and my memory is a little rusted. However, I
remember seeing this log when I was upgrading my Shibboleth from 4.3 to 5
(idp with Jetty on Debian). I don't think that idp is loaded and that is
why it is not logging. It is complaining [2025-01-17 14:02:29] [info] At
least one JAR was scanned for TLDs yet contained no TLDs.
In my case I remember that got to do with the Jetty-base files - The
Jetty-base file that were working with jetty 9 were not working for jetty
11/12 so I have to get the shibboleth jetty-base file from the Internet.
You may have an equivalent problem with Tomcat.
HTH,
Equbay Kiflay
On Tue, Jan 21, 2025 at 9:54 AM Wessel, Keith via users <
users at shibboleth.net> wrote:
> Hi, all,
>
>
>
> I’m rather stumped here and am hoping for some direction of where to look
> next.
>
>
>
> I’m helping another campus upgrade from IdP 4 to IdP 5. They’re running on
> a Ubuntu server that they upgraded from 22.04 to 24.04 to get access to
> Tomcat 10. They also upgraded from Tomcat 9 to 10 and Java 8 to 17.
>
>
>
> Tomcat’s starting, and it’s deploying the IdP. This from Catalina.out:
>
>
>
> [2025-01-17 14:02:25] [info] Deploying deployment descriptor
> [/etc/tomcat10/Catalina/localhost/idp.xml]
>
> [2025-01-17 14:02:25] [warning] Deployment of deployment descriptor
> [/etc/tomcat10/Catalina/localhost/idp.xml] with an external docBase means
> the directory [/var/lib/tomcat10/webapps/idp] in the appBase will be ignored
>
> [2025-01-17 14:02:29] [info] At least one JAR was scanned for TLDs yet
> contained no TLDs. Enable debug logging for this logger for a complete list
> of JARs that were scanned but no TLDs were found in them. Skipping unneeded
> JARs during scanning can improve startup time and JSP compilation time.
>
> [2025-01-17 14:02:31] [info] 2025-01-17 14:02:31.766 [ WARN] : DEPRECATED:
> Java class 'net.shibboleth.idp.profile.logic.SimpleAttributePredicate':
> This will be removed in the next major version of this software;
> replacement is Parent bean 'shibboleth.Conditions.SimpleAttribute'
>
> [2025-01-17 14:02:37] [info] Deployment of deployment descriptor
> [/etc/tomcat10/Catalina/localhost/idp.xml] has finished in [12,077] ms
>
>
>
> But trying to access the IdP (we’re just trying /dip/status) gives us an
> error page which looks like it’s coming out of the IdP, but I can’t say for
> sure. It contains:
>
>
>
> An error occurred: ServletException
>
>
>
> The IdP isn’t writing any log files even though the IdP log directory is
> writeable by the Tomcat user. We also turned off SELinux to make sure it
> wasn’t somehow interfering. And we’re not seeing any obvious errors when we
> hit /idp/status in any of the Tomcat logs.
>
>
>
> With no other errors to go on, I’m stuck. Any suggestions?
>
>
>
> Thanks,
>
> Keith
>
>
> --
> For Consortium Member technical support, see
> https://shibboleth.atlassian.net/wiki/x/ZYEpPw
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
--
<https://concordia.ab.ca/>
[image: Concordia University of Edmonton] <https://concordia.ab.ca/>
Equbay Kiflay <equbay.kiflay at concordia.ab.ca>
IT Operations Coordinator
Information Technology Services
Office +1 +1 780 378 8474
TF +1 866 479 5200
equbay.kiflay at concordia.ab.ca
concordia.ab.ca
*Concordia University of Edmonton is located on Indigenous lands and
territories now called Treaty No. 6 territory and the homeland of the Métis
Nation (District 9). We honor and respect the agreements made by our
ancestors to live in good relations for as long as the sun shines, the
grass grows, and the river flows.*
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20250121/102c1cd2/attachment.htm>
More information about the users
mailing list