<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
{font-family:Consolas;
panose-1:2 11 6 9 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:12.0pt;
font-family:"Times New Roman",serif;
color:black;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:#0563C1;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:#954F72;
text-decoration:underline;}
pre
{mso-style-priority:99;
mso-style-link:"HTML Preformatted Char";
margin:0in;
margin-bottom:.0001pt;
font-size:10.0pt;
font-family:"Courier New";
color:black;}
tt
{mso-style-priority:99;
font-family:"Courier New";}
span.HTMLPreformattedChar
{mso-style-name:"HTML Preformatted Char";
mso-style-priority:99;
mso-style-link:"HTML Preformatted";
font-family:Consolas;
color:black;}
span.EmailStyle20
{mso-style-type:personal;
font-family:"Calibri",sans-serif;
color:#1F497D;}
span.EmailStyle21
{mso-style-type:personal-reply;
font-family:"Calibri",sans-serif;
color:#1F497D;}
.MsoChpDefault
{mso-style-type:export-only;
font-size:10.0pt;}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body bgcolor="white" lang="EN-US" link="#0563C1" vlink="#954F72">
<div class="WordSection1">
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">Thanks, Brent, especially for the lead to the file cache dir.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">I see that it is empty after shutdown, and after start-up the files are pulled down and stored. So, the 304 message I was seeing in the webserver log from the
server hosting the attribute filter files must have been a subsequent fetch, though I didn’t see that in the logs. I can look again. At any rate, I’m getting valid files in the cache dir; they’re just not getting created in the IDP conf dir.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">And yes, when I mentioned manually pulling them down, I meant wgetting the files and dropping them in place where the IDP would store them in the conf dir before
starting the IDP. Interestingly when I do this then start the IDP, it does update these files, or at least update their timestamps. I did this before noon and left the IDP running, and the attribute filter files in the conf dir were having their timestamps
updated every 15 minutes as appropriate.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">So, with all this said, which of the classes do you want me to provide debug-level logging for in Gira?<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">Keith<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><o:p> </o:p></span></p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:windowtext">From:</span></b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:windowtext"> users [mailto:users-bounces@shibboleth.net]
<b>On Behalf Of </b>Brent Putman<br>
<b>Sent:</b> Tuesday, July 21, 2015 2:33 PM<br>
<b>To:</b> users@shibboleth.net<br>
<b>Subject:</b> Re: Configuring a file-backed HTTP resource for attribute filters<o:p></o:p></span></p>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal" style="margin-bottom:12.0pt"><o:p> </o:p></p>
<div>
<p class="MsoNormal">On 7/21/15 2:46 PM, Wessel, Keith wrote:<o:p></o:p></p>
</div>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><br>
<br>
</span><o:p></o:p></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"> </span><o:p></o:p></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">Where shall we start? First, this file cache you referred to. That’s an in-memory cache?
</span><o:p></o:p></p>
</blockquote>
<p class="MsoNormal"><br>
Well, based on looking at the Spring XML Rod gave you earlier in the thread, it looked like you were probably using shibboleth.FileCachingHttpClient. So that's a filesystem-based cache. The actual cache directory for that is defined in services.properties
as 'idp.httpclient.filecaching.cacheDirectory'. It defaults to: %{idp.home}/tmp/httpClientCache. So what you might do is shutdown, clear out that directory, restart and see what's there.
<br>
<br>
<br>
<br>
<o:p></o:p></p>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">Something that gets cleaned out by a restart? ‘Cause this error occurs on jetty/IDP start-up.</span><o:p></o:p></p>
</blockquote>
<p class="MsoNormal"><br>
As I mentioned later in the thread, I think that an IdP shutdown *should* be clearing this directory out. If you do the above to get it to a known good state, you should see stuff there. If you then shut down again, I think you should see it empty again.<br>
<br>
So my initial guess was probably wrong. For that and another reason, I don't think you should effectively see HttpClient-level caching across restarts.<br>
<br>
However, what you might be seeing is: First, a call to check whether the resource exists() happen earlier (don't know for sure, we need to check), and then a second call to actually get the resource. The second would be served from cache, which was populated
by the first call.<br>
<br>
<br>
<br>
<o:p></o:p></p>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">So, if it’s in-memory, I should be starting with a clean cache and without the local backin file existing.
</span><o:p></o:p></p>
</blockquote>
<p class="MsoNormal"><br>
The backing file is something else. That's *our* (OpenSAML/IdP) backup file for the HTTP resource. AFAIK, that *should* persist across restarts.<br>
<br>
<br>
<br>
<o:p></o:p></p>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">BTW, when I do suck downthe file manually before starting the IDP, the warnings go away and the IDP happily accepts the 304 return code.</span><o:p></o:p></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"> </span><o:p></o:p></p>
</blockquote>
<p class="MsoNormal"><br>
Sorry, what do you mean by this exactly? How are you sucking it down outside of the IdP? Do you mean you are manually downloading it and storing it in the backing file location? If so, then I understand and that's what's supposed to happen (although obviously
you're not supposed to have to do that...)<br>
<br>
Also, exactly where are you seeing this 304 return code? Can you post either here or in Jira the exact log message and some of surrounding log messages, for context?<br>
<br>
<br>
<br>
<o:p></o:p></p>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D">Shall I try turning up logging as Brent suggested and see what that tells me? And perhaps, if there’s nothing obvious in the output, put that output in Gira?</span><o:p></o:p></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D"><br>
<br>
</span><o:p></o:p></p>
</blockquote>
<p class="MsoNormal" style="margin-bottom:12.0pt"><br>
<br>
That will certainly tell us more about what's going on. So please do so if/when you have the time.<br>
<br>
<br>
<br>
<o:p></o:p></p>
</div>
</body>
</html>