<div dir="ltr"><div><div><div><div>Hello,<br></div>I was hoping to get some assistance with an issue we've run into at the AAF with shibd.<br><br></div>We've recently switched the SP exhibiting the fault described below to our new metadata source so I am certainly of the opinion that either this new metadata source or our SP configuration, is going to be the root cause here but after exhausting all the diagnostic avenues I can think of I was hoping someone else may be able to point me in a direction I've not considered.<br></div><br></div><div>The problem we're seeing occurs when our shibd instance is restarted. When the upstream metadata document matches what has been previously cached locally, signature verification fails, taking down the service. Signature verification does not fail and the service functions correctly, when the upstream metadata has changed and is re-downloaded after restart.<br><br></div><div>I've gathered a reasonable amount of logging/detail about this and instead of cramming it all into an unreadable form in this email I've collated it at <a href="https://gist.github.com/bradleybeddoes/c3b3d1cef20d60c577f3" target="_blank">https://gist.github.com/bradleybeddoes/c3b3d1cef20d60c577f3</a><br><br></div><div>This gist shows:<br><br></div><div>0: is simply informational, our local versions etc<br></div><div>1: shows the log output on an erroneous shibd restart<br></div><div>2: shows the log output on a successful restart where I've removed the cached metadata and tag files from local disk prior, forcing download (or upstream has legitimately changed - I've checked with both scenarios, same logging).<br></div><div>3: our source metadata document (Full XML at <a href="https://md.aaf.edu.au/aaf-metadata.xml" target="_blank">https://md.aaf.edu.au/aaf-metadata.xml</a>)<br></div><div>4: the cached metadata document from /var/cache/shibboleth - I do note there are minor differences<br></div><div>5:
 xmlsectool output, noting that for the 'same' document, based on 
EntitiesDescriptor ID, we're getting a failed digest calculation from the version recovered from /var/cache/shibboleth.<br></div><div><br></div><div>Thus far I've:</div><ul><li>Been able to recreate the behavior described above at random times over a few days;</li><li>Looked extensively at our distribution endpoints for something invalid coming back following request for the source document, <br>but I can't see any anomalies at that layer at this time;</li><li>Looked into our historical metadata source document cache and successfully verified them with xmlsectool;</li><li>Confirmed that a 2.4.x IdP on the same server has not exhibited any errors in metadata loading/verification;</li><li>Searched this list and the issue tracker for something similar to no avail.</li></ul>Thanks in advance for any help.<br><p>cheers,<br>Bradley<span class=""><font color="#888888"><br></font></span></p>-- <br><div class="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div style="font-size:11pt;margin:0cm 0cm 0.0001pt">
<font face="arial, helvetica, sans-serif"><b><span style="font-size:9pt;color:rgb(227,108,10)">Bradley Beddoes</span></b><font color="#666666"> <span style="font-size:8.5pt">| Technical Lead - Innovation, Software Development and Infrastructure<br><b>Australian Access Federation Inc</b></span></font></font></div><span style="text-align:-webkit-auto"></span><span style="font-family:arial,helvetica,sans-serif"></span></div></div></div></div></div></div></div></div></div></div>
</div>