<div dir="ltr">I was just wondering this myself. I also used the aacli utility to make sure the attributes were being released correctly before I reloaded the configuration. And when I ran the v3 one to see if things looked OK for a new SP I added, only the 'release to anyone' attributes were in the assertion. I couldn't for the life of me see what was wrong with my configuration. This is when I thought, check the list.<div><br></div><div>It *is* nice to be able to sort of pre-check the configuration. Reloading our v2 IdP has become a pretty drawn-out process (possibly since we started including the whole set of InCommon metadata), so knowing if things are set up correctly before waiting for the restart is really valuable. But maybe with the switch to Jetty and the new IdP in general, that won't be as much of a problem. (Our v3 IdP is not production yet.)</div></div><div class="gmail_extra"><br><div class="gmail_quote">On Fri, Oct 30, 2015 at 9:49 AM, Martin Haase <span dir="ltr"><<a href="mailto:Martin.Haase@daasi.de" target="_blank">Martin.Haase@daasi.de</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">A follow-up...<br>
<br>
I noticed that the 'new aacli' does not operate on the<br>
attribute-resolver.xml as it is currently on disk, but as it has been<br>
loaded into the IdP already. Is that correct?<br>
<br>
This would mean there is no chance to test an updated resolver<br>
configuration before it goes life?<br>
<br>
In that case there is not much use in having it, which is a real pity.<br>
<br>
Regards,<br>
Martin<br>
<div class="HOEnZb"><div class="h5"><br>
Am 06.10.2015 um 09:33 schrieb Martin Haase:<br>
> Answering my own question:<br>
><br>
> just do a<br>
><br>
> curl -k<br>
> '<a href="https://host:443/idp/profile/admin/resolvertest?requester=https%3A%2F%2F" rel="noreferrer" target="_blank">https://host:443/idp/profile/admin/resolvertest?requester=https%3A%2F%2F</a><sp-host-address>%2Fshibboleth&principal=<principalname>'<br>
><br>
> ...quite simple actually... :)<br>
><br>
> Cheers,<br>
> Martin<br>
><br>
><br>
><br>
> Am 06.10.2015 um 09:23 schrieb Martin Haase:<br>
>> Dear list,<br>
>> I have problems using the v3 AACLI interface. Most of our IdP<br>
>> installations have Apache in front of Tomcat, with only port 443<br>
>> accessible. We cannot use the default configuration (without -u) as we<br>
>> do not wish to open up the additional HTTP port 80. However, including<br>
>> the "-u <a href="https://host:443" rel="noreferrer" target="_blank">https://host:443</a>" switch, using an otherwise valid Web Server<br>
>> certificate in Apache, aacli seems to be unable to verify this OOTB. The<br>
>> only way to manage this seems to import the Apache certificates/trust<br>
>> chain into some keystore, and using the -tp, -ts, and -tt options, which<br>
>> is quite impractical given the number of IdP instances we maintain.<br>
>><br>
>> Given aacli can only be called from localhost, a certificate check seems<br>
>> to be little useful. Thus, is there any way to invoke the new aacli,<br>
>> telling it to not verify/validate the server certificate?<br>
>><br>
>> Regards,<br>
>> Martin<br>
>><br>
<br>
--<br>
Dr. Martin Haase, Solutions Engineer<br>
<br>
DAASI International GmbH<br>
Europaplatz 3<br>
D-72072 Tübingen<br>
Germany<br>
<br>
phone: <a href="tel:%2B49%207071%20407109-6" value="+4970714071096">+49 7071 407109-6</a><br>
fax:   <a href="tel:%2B49%207071%20407109-9" value="+4970714071099">+49 7071 407109-9</a><br>
email: <a href="mailto:martin.haase@daasi.de">martin.haase@daasi.de</a><br>
web:   <a href="http://www.daasi.de" rel="noreferrer" target="_blank">www.daasi.de</a><br>
<br>
Sitz der Gesellschaft: Tübingen<br>
Registergericht: Amtsgericht Stuttgart, HRB 382175<br>
Geschäftsleitung: Peter Gietz<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a></div></div></blockquote></div><br><br clear="all"><div><br></div>-- <br><div class="gmail_signature"><div style="margin-left:40px">Karla Borecky<br>Systems Administrator<br>ITS<br>Smith College<br>Northampton, MA 01063<br></div></div>
</div>