<div dir="ltr">Thanks Brent and Peter!<div><br></div><div>I&#39;ve been doing some tests and know I&#39;m getting an error about not finding metadata of the service provider:</div><div><br></div><div>.......</div><div><br>
</div><div><div>17:04:10.612 - DEBUG [org.opensaml.saml2.metadata.provider.ChainingMetadataProvider:253] - Checking child metadata provider for entity descriptor with entity ID: <a href="http://google.com/a/mygoogledomain.com">google.com/a/mygoogledomain.com</a></div>
<div>17:04:10.613 - DEBUG [org.opensaml.saml2.metadata.provider.AbstractMetadataProvider:518] - Searching for entity descriptor with an entity ID of <a href="http://google.com/a/mygoogledomain.com">google.com/a/mygoogledomain.com</a></div>
<div>17:04:10.613 - TRACE [org.opensaml.saml2.metadata.provider.AbstractMetadataProvider:531] - Metadata root is an entity descriptor, checking if it&#39;s the one we&#39;re looking for.</div><div>17:04:10.614 - TRACE [org.opensaml.saml2.metadata.provider.AbstractMetadataProvider:538] - Found entity descriptor for entity with ID <a href="http://google.com/a/mygoogledomain.com">google.com/a/mygoogledomain.com</a> but it is no longer valid, skipping it.</div>
<div>17:04:10.615 - DEBUG [org.opensaml.saml2.metadata.provider.AbstractMetadataProvider:167] - Metadata document does not contain an EntityDescriptor with the ID <a href="http://google.com/a/mygoogledomain.com">google.com/a/mygoogledomain.com</a></div>
<div>17:04:10.615 - WARN [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:287] - No metadata for relying party <a href="http://google.com/a/mygoogledomain.com">google.com/a/mygoogledomain.com</a>, treating party as anonymous</div>
<div>17:04:10.616 - WARN [edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler:220] - SAML 2 SSO profile is not configured for relying party <a href="http://google.com/a/mygoogledomain.com">google.com/a/mygoogledomain.com</a></div>
<div>17:04:10.653 - TRACE [edu.internet2.middleware.shibboleth.idp.session.IdPSessionFilter:109] - Attempting to retrieve IdP session cookie.</div></div><div><br></div><div>As you can see, from my original post, the entity descriptor was found in the index cache, and because of that it worked ok. Now, from the log of this post, it can&#39;t found the descriptor in the cache and it&#39;s treating the relying party as anonymous and make sense that it can&#39;t find the SSO profile. So:</div>
<div><br></div><div>How Shib adds the descriptor in the cache? and when? (I suspect this has to do with the <strong style="font-size:13.333333015441895px;margin-top:0px;margin-bottom:0px;color:rgb(51,51,51);font-family:Arial,Helvetica,FreeSans,sans-serif;line-height:17.33333396911621px">refreshDelayFactor</strong><span style="font-size:13.333333015441895px;margin-top:0px;margin-bottom:0px;color:rgb(51,51,51);font-family:Arial,Helvetica,FreeSans,sans-serif;line-height:17.33333396911621px"> and the other attributes)</span></div>
<div><br></div><div>Is there a way of resetting the cache?</div><div><br></div><div>How can I add the descriptor to the cache?</div><div><br></div><div>I did another test and I reinstalled shibb (install.sh) and add again the relying party and metadata, and everything start working again with the same log from my first post. Any idea why this happens?</div>
<div><br></div><div>Peter I don&#39;t understand:</div><div><br></div><div><font color="#a64d79"><span style="font-family:arial,sans-serif;font-size:13px">&gt; Note that for locally managed metadata there&#39;s no gain in having any</span><br style="font-family:arial,sans-serif;font-size:13px">
<span style="font-family:arial,sans-serif;font-size:13px">&gt; validUntil on the EntityDescriptor. So leaving that out is one</span><br style="font-family:arial,sans-serif;font-size:13px"><span style="font-family:arial,sans-serif;font-size:13px">&gt; possibility.</span></font></div>
<div><font color="#a64d79"><br></font></div><div>Since you mention that validUntil is useless in this context, how can I make a local managed metadata expired?<font color="#a64d79"><br></font></div><div><font color="#a64d79"><br style="font-family:arial,sans-serif;font-size:13px">
<span style="font-family:arial,sans-serif;font-size:13px">&gt; The other one is setting requireValidMetadata=&quot;false&quot; on the IdP&#39;s</span><br style="font-family:arial,sans-serif;font-size:13px"><span style="font-family:arial,sans-serif;font-size:13px">&gt; MetadataProvider for that custom relying party, but I see you already</span><br style="font-family:arial,sans-serif;font-size:13px">
<span style="font-family:arial,sans-serif;font-size:13px">&gt; have that (so either way an expired EntityDescriptor from a local file</span><br style="font-family:arial,sans-serif;font-size:13px"><span style="font-family:arial,sans-serif;font-size:13px">&gt; shouldn&#39;t disrupt operations).</span><br style="font-family:arial,sans-serif;font-size:13px">
<span style="font-family:arial,sans-serif;font-size:13px">&gt; -peter</span></font><br></div><div><br></div><div>is not that what is happening? (the operation it&#39;s been disrupted). Due the fact that the EntityDescriptor is not valid (I&#39;m assuming that the reason is because it has expired) is showing that it&#39;s treating the relyingParty as anonymous, right?</div>
<div><br></div><div><br></div><div>Thanks for all the help.</div><div><br></div><div>Best,</div><div><br></div><div>Thomas.</div><div> </div><div><br></div><div class="gmail_extra"><div class="gmail_quote">On Thu, Oct 31, 2013 at 5:09 AM, Peter Schober <span dir="ltr">&lt;<a href="mailto:peter.schober@univie.ac.at" target="_blank">peter.schober@univie.ac.at</a>&gt;</span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);border-left-style:solid;padding-left:1ex">* Thomas Jones &lt;<a href="mailto:thomas.jones.g@gmail.com">thomas.jones.g@gmail.com</a>&gt; [2013-10-30 23:31]:<br>

<div class="im">&gt; I&#39;ve tried to add the attribute validUntil to my SP metadata but<br>
&gt; there&#39;s no difference:<br>
&gt;<br>
&gt;<br>
&gt; &lt;?xml version=&quot;1.0&quot; encoding=&quot;UTF-8&quot;?&gt;<br>
&gt; &lt;EntityDescriptor entityID=&quot;<a href="http://google.com/a/mygoogledomain.com" target="_blank">google.com/a/mygoogledomain.com</a>&quot;<br>
&gt; xmlns=&quot;urn:oasis:names:tc:SAML:2.0:metadata&quot;<br>
&gt; validUntil=&quot;2014-01-01T00:00:00Z&quot;&gt;<br>
<br>
</div>Note that for locally managed metadata there&#39;s no gain in having any<br>
validUntil on the EntityDescriptor. So leaving that out is one<br>
possibility.<br>
The other one is setting requireValidMetadata=&quot;false&quot; on the IdP&#39;s<br>
MetadataProvider for that custom relying party, but I see you already<br>
have that (so either way an expired EntityDescriptor from a local file<br>
shouldn&#39;t disrupt operations).<br>
-peter<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div><br></div></div>