Jetty unresponsive for shibboleth IDP requests
Dewi Aled JONES
aled.jones at ist.ac.at
Tue May 20 08:28:48 UTC 2025
Hello all,
I have very little experience with shibboleth, and need to fix an urgent problem while the person who normally maintains the system is away.
The IDP system was working fine for many weeks but suddenly stopped responding one morning. The IDP URL timedout.
Restarting Jetty service brought the IDP back responsive, but after approx. 15mins, same issue occurred.
I also see that even after a jetty restart some of our services cannot authenticate, they just hang waiting for IDP, whilst others redirect to IDP and allow login.
As a workaround, Ive set a cronjob to restart jetty every 30mins. but as noted above, this only allows auth to some of our services, not all.
Details:
cat /opt/jetty-base-idp/jetty.state
INIT StateLifeCycleListener at 662b4c69
STARTING oejs.Server at 5a7fe64f{STARTING}[12.0.16,sto=0]
STARTED oejs.Server at 5a7fe64f{STARTED}[12.0.16,sto=0]
/opt/shibboleth-idp/bin/version.sh
5.1.3
cat /etc/debian_version
11.10
There is nothing obvious in the 'idp-process.log' or the 'jetty.log'.
An external partner with many years experience with shibboleth has had a look for a few hours, but was unable to find the problem.
In our configuration, we define each metadata instead of an automatic directory config, but this has been ok for many years. (just over 100 metadata definitions).
Running '/opt/shibboleth-idp/bin/status.sh' never completes, perhaps this gives a clue?
Any troubleshooting tips appreciated.
Many thanks!
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20250520/2065d01e/attachment.htm>
More information about the users
mailing list