<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Exchange Server">
<!-- converted from text --><style><!-- .EmailQuote { margin-left: 1pt; padding-left: 4pt; border-left: #800000 2px solid; } --></style>
</head>
<body>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:11pt; color:black">
<span style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:11pt; color:black">Yes, java remained at ver 8 for both 9.3 and 9.2, so it seems like a jetty issue.<br>
<br>
<br>
<br>
<span style="color:black">-----Original Message----- <br>
<b>From:</b> Cantor, Scott [cantor.2@osu.edu]<br>
<b>Received:</b> Monday, 03 Aug 2015, 7:25PM<br>
<b>To:</b> Shib Users [users@shibboleth.net]<br>
<b>Subject:</b> Re: idp login issue connecting to ldap<br>
<br>
</span></span></div>
<font size="2"><span style="font-size:10pt;">
<div class="PlainText">On 8/3/15, 8:13 PM, "users on behalf of Paul Caskey" <users-bounces@shibboleth.net on behalf of pcaskey@internet2.edu> wrote:<br>
<br>
<br>
<br>
>First, I have not read this entire thread, so my apologies if this is completely off-base, but it might be relevant.  I was recently working on a new V3 IdP and ran into an issue where trying to login (via the normal login form) resulted in a simple re-display
 of the login page with no displayed errors and no messages written to idp-process.log, even with ldaptive and idp in DEBUG.<br>
<br>
Sounds similar.<br>
<br>
>I was running Jetty 9.3.  I reverted to 9.2 and then started getting errors messages in idp-process.log.  The errors basically indicated that I had not installed the JCE, which I had overlooked (error was invalid key length for the sealer key, IIRC).  That
 IdP is now running fine on Jetty 9.2 (with JCE), I never went back to 9.3.  <br>
<br>
I assume you mean "with full-strength policy files", the JCE is there regardless.<br>
<br>
That's more likely to be a Java 7 vs. 8 issue than Jetty (were you still on 8?), but more to the point I can't off-hand think of a connection between that component and this particular part of the system.<br>
<br>
The policy isn't supposed to matter for AES-128, but that never seems to be very consistent, and we just documented it as requiring the full-strength files regardless.<br>
<br>
-- Scott<br>
<br>
-- <br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font>
</body>
</html>