<p dir="ltr">Has your VM been running all along or has the state simply been saved in the meantime? This could very well cause time and date issues with your VM... </p>
<p dir="ltr">And yes, it's a small world, my friend ;-) </p>
<div class="gmail_quote">On Oct 12, 2015 10:31, "Daniel Smedegaard Buus" <<a href="mailto:danielbuus@gmail.com">danielbuus@gmail.com</a>> wrote:<br type="attribution"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">LOL, hi Søren :D Funny finding you here :) How's it going?<br>
<br>
Well, it's pretty strange — I have the SP configured as a relying<br>
party on the IdP with a MatadataProvider.maxValidityInterval="P1D", so<br>
it should be one day...<br>
<br>
Restarting tomcat on that machine made Shibboleth error out<br>
immediately on starting with the same error while loading the<br>
metadata. I then set it to P1M, and it works fine again.<br>
<br>
In fact, the only change since Friday, is that more than 1 day has<br>
passed, so I guess something's amiss there. The SP fetadata is<br>
generated on each request, and the http cache headers are set to 1<br>
hour.<br>
<br>
I do note upon Googling, that some related bugs were fixed in 2.4, and<br>
this IDM virtual machine is running 2.3.3.<br>
<br>
I'm really just testing against it, and I'm gonna kill it eventually,<br>
so I guess I'l just have to make a client requirement of anyone using<br>
Shibboleth to be fully upgraded and knowledgable about how to use it<br>
(more than I am, anyway ;) )<br>
<br>
Does this sound like something 2.3.3 might have probs with to you?<br>
<br>
Cheers,<br>
Daniel :)<br>
<br>
On Mon, Oct 12, 2015 at 10:16 AM, Søren Grønning <<a href="mailto:s.groening@gmail.com">s.groening@gmail.com</a>> wrote:<br>
> Hi Daniel<br>
><br>
> What is your 'valid until' metadata value set to on both IdP and SP?<br>
><br>
> It would seem to be a conflict between the two values that causes the error.<br>
><br>
> It seems similar to this occurrence :<br>
><br>
> <a href="https://lists.internet2.edu/sympa/arc/shibboleth-users/2008-11/msg00343.html" rel="noreferrer" target="_blank">https://lists.internet2.edu/sympa/arc/shibboleth-users/2008-11/msg00343.html</a><br>
><br>
> Best regards,<br>
><br>
> Søren Grønning<br>
><br>
> On Oct 12, 2015 10:02, "Daniel Smedegaard Buus" <<a href="mailto:danielbuus@gmail.com">danielbuus@gmail.com</a>><br>
> wrote:<br>
><br>
> Hey everyone :)<br>
><br>
> I'm new to Shibboleth. I've been integrating a website with WebSSO,<br>
> covering first ADFS, then Okta, and now I'm testing against<br>
> Shibboleth. I've been using the CentOS pre-configued VirtualBox IdP<br>
> image provided by IDM to test against, and I had some obstacles at<br>
> first that I needed to work through, among those a missing validUntil<br>
> attribute on my SP's federation metadata.<br>
><br>
> I initially set it to a day, thinking that seemed alright, but got<br>
> errors from Shibboleth that it was longer than what was allowed. I<br>
> don't remember what the exact allowance was, but I then set it to an<br>
> hour instead, and Shibboleth was then happy for all of Friday while I<br>
> was testing.<br>
><br>
> Weird thing is, this morning after the weekend, I open up my laptop,<br>
> and I now see that Shibboleth is erroring out in its log, saying,<br>
><br>
> Error filtering metadata from<br>
> <a href="https://browsertest.localhost/login/sso/metadata.xml" rel="noreferrer" target="_blank">https://browsertest.localhost/login/sso/metadata.xml</a><br>
> org.opensaml.saml2.metadata.provider.FilterException: Metadata's<br>
> validity interval, 237588141ms, is larger than is allowed, 86400000ms.<br>
><br>
> So now the allowed interval is 24 minutes? I haven't configured<br>
> anything other than filters and resolvers, and haven't touched the<br>
> machine during the weekend, so I'm a bit puzzled here. I can't find<br>
> anyone on Google with questions regarding these 86400000ms, so it<br>
> looks like I might be alone with this config...<br>
><br>
> Is 24 minutes really the default? I've seen Google results hinting at<br>
> a default max of 70 days...<br>
><br>
> TIA,<br>
> Daniel<br>
> --<br>
> To unsubscribe from this list send an email to<br>
> <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
><br>
><br>
> --<br>
> To unsubscribe from this list send an email to<br>
> <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a></blockquote></div>