<div dir="ltr"><div class="gmail_default" style="font-family:courier new,monospace">The first scenario is sort of hit or miss so let me figure that one out, but the second issue trying to use the resolver is pretty consistent:<br><br></div><div class="gmail_default" style="font-family:courier new,monospace">In ldap.properties<br>idp.authn.LDAP.sslConfig                        = jvmTrust<br>idp.authn.LDAP.trustCertificates                = %{idp.home}/credentials/ldap-server.crt<br><br></div><div class="gmail_default" style="font-family:courier new,monospace">However ldap-server.crt file doesn't exist:, then excecute:<br>shibboleth-idp/bin/reload-service.sh -id shibboleth.AttributeResolverService<br><br></div><div class="gmail_default" style="font-family:courier new,monospace">Then the idp-process-log file starts error out. If I comment out idp.authn.LDAP.trustCertificates, then it says it's not set<br></div><div class="gmail_default" style="font-family:courier new,monospace"><br><br></div><div class="gmail_extra"><br clear="all"><div><div class="gmail_signature"><div dir="ltr"><font face="courier new, monospace">Jeffrey E. Crawford<br>ITS Application Administrator (IdM)<br>831-459-4365<br><a href="mailto:jeffreyc@ucsc.edu" target="_blank">jeffreyc@ucsc.edu</a></font><div><font face="courier new, monospace"><br></font></div><div><font face="courier new, monospace">Both pilots and IT professionals require training and currency before charging into clouds!<br></font></div><div><font face="courier new, monospace">---------------------------------------</font></div></div></div></div>
<br><div class="gmail_quote">On Fri, May 8, 2015 at 8:24 PM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><span class="">> > but trying to set idp.authn.LDAP.sslConfig=jvmTrust has been making the<br>
> > software kinda go haywire.<br>
<br>
</span>Can you identify which service you reloaded that caused the error? That doesn't seem to be obviously reproducible to me, and really it shouldn't be possible. If the file were needed and wasn't present, that should be true initially or afterward.<br>
<br>
That might be a function of just being confused about the changes, and accidentally putting in a config choice that did actually depend on that cert file being present.<br>
<div class=""><div class="h5"><br>
-- Scott<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br></div></div>