<div dir="ltr">Thanks Scott!<div><br></div><div>That could be it ---- I inherited the service so have not touched other nameID configs -- worried that may break other things.</div><div><br></div><div>Could the following old AttributeDefinition clash with the new <span style="color:rgb(57,51,255);font-family:Monaco;font-size:11px">StoreID - </span><span style="font-family:Monaco;font-size:11px"><font color="#000000">listed</font></span><span style="color:rgb(57,51,255);font-family:Monaco;font-size:11px"> </span>below in the thread? The old derives the 'uid' from a straight LDAP query -- with no persistent configs.</div><div><font color="#000000"><br></font></div><div><font color="#000000">I am still puzzled as the new <span style="font-family:Monaco;font-size:11px">StoreID writes & salts to the DB (which we did not have previously).</span></font></div><div><br></div><div><div><br></div><div><p style="margin:0px;font-size:11px;line-height:normal;font-family:Monaco;color:rgb(57,51,255)"><span style="color:rgb(0,0,0)"> </span><span style="color:rgb(0,145,147)"><</span><span style="color:rgb(78,145,146)">resolver:AttributeDefinition</span><span style="color:rgb(0,0,0)"> </span><span style="color:rgb(147,33,146)">id</span><span style="color:rgb(0,0,0)">=</span>"NameID"<span style="color:rgb(0,0,0)"> </span><span style="color:rgb(147,33,146)">xsi:type</span><span style="color:rgb(0,0,0)">=</span>"Simple"<span style="color:rgb(0,0,0)"> </span><span style="color:rgb(147,33,146)">xmlns</span><span style="color:rgb(0,0,0)">=</span>"urn:mace:shibboleth:2.0:resolver:ad"<span style="color:rgb(0,0,0)"> </span><span style="color:rgb(147,33,146)">sourceAttributeID</span><span style="color:rgb(0,0,0)">=</span>"uid"<span style="color:rgb(0,145,147)">></span></p>
<p style="margin:0px;font-size:11px;line-height:normal;font-family:Monaco;color:rgb(78,145,146)"><span style="color:rgb(0,0,0)"><span class="gmail-Apple-tab-span" style="white-space:pre">           </span>      </span><span style="color:rgb(0,145,147)"><</span>resolver:Dependency<span style="color:rgb(0,0,0)"> </span><span style="color:rgb(147,33,146)">ref</span><span style="color:rgb(0,0,0)">=</span><span style="color:rgb(57,51,255)">"ldapLookup"</span><span style="color:rgb(0,0,0)"> </span><span style="color:rgb(0,145,147)">/></span></p>
<p style="margin:0px;font-size:11px;line-height:normal;font-family:Monaco;color:rgb(78,145,146)"><span style="color:rgb(0,0,0)"><span class="gmail-Apple-tab-span" style="white-space:pre">           </span>      </span><span style="color:rgb(0,145,147)"><</span>resolver:AttributeEncoder<span style="color:rgb(0,0,0)"> </span><span style="color:rgb(147,33,146)">xsi:type</span><span style="color:rgb(0,0,0)">=</span><span style="color:rgb(57,51,255)">"SAML2StringNameID"</span><span style="color:rgb(0,0,0)"> </span></p>
<p style="margin:0px;font-size:11px;line-height:normal;font-family:Monaco;color:rgb(57,51,255)"><span style="color:rgb(0,0,0)"><span class="gmail-Apple-tab-span" style="white-space:pre">            </span>      <span class="gmail-Apple-tab-span" style="white-space:pre">                                     </span></span><span style="color:rgb(147,33,146)">xmlns</span><span style="color:rgb(0,0,0)">=</span>"urn:mace:shibboleth:2.0:attribute:encoder"</p>
<p style="margin:0px;font-size:11px;line-height:normal;font-family:Monaco;color:rgb(57,51,255)"><span style="color:rgb(0,0,0)"><span class="gmail-Apple-tab-span" style="white-space:pre">            </span>                <span class="gmail-Apple-tab-span" style="white-space:pre">              </span></span><span style="color:rgb(147,33,146)">nameFormat</span><span style="color:rgb(0,0,0)">=</span>"urn:oasis:names:tc:SAML:2.0:nameid-format:unspecified"<span style="color:rgb(0,0,0)"> </span><span style="color:rgb(0,145,147)">/></span></p>
<p style="margin:0px;font-size:11px;line-height:normal;font-family:Monaco;color:rgb(78,145,146)"><span style="color:rgb(0,0,0)">       </span><span style="color:rgb(0,145,147)"></</span>resolver:AttributeDefinition<span style="color:rgb(0,145,147)">></span></p></div></div></div><div class="gmail_extra"><br><div class="gmail_quote">On Thu, Jul 20, 2017 at 2:18 PM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">> Here is the odd thing -- rebooting, without changing config files, still works<br>
> for all -- including PersistentID -- & the error message still occurs on a<br>
> scheduled basis.<br>
<br>
</span>I think you have a non-failfast NameID generation service config, and you have a legacy resolver configuration that's doing NameID generation and it's basically backstopping and doing the work you think these settings are doing. I can't think of any other obvious answer.<br>
<span class=""><br>
> Quite stumped......is there something not right in config below?<br>
<br>
</span>There's nothing anybody could eyeball, this is a Spring runtime error in a system bean whose problem is with the runtime behavior of the components, I doubt it's a syntactic problem.<br>
<br>
> attribute-resolver.xml<br>
<br>
Thus my point. There is nothing in attribure-resolver.xml that has anything to do with a system that's supposed to be operating based on the saml-nameid files and properties. You pick one, not both. Old, new. You will find nothing in the NameIDGeneration topics that refer to the resolver or expect you to set anything there, so you are inherently doing something we do not expect you to do.<br>
<br>
Probably one's working and one isn't. I thought we normally set the generation service to fail-fast, but I don't have it in front of me.<br>
<br>
Basically, your system is not using the settings you seem to believe it is. You're changing settings for the new features, it's not functioning, and the old settings in the resolver that are deprecated are still there and running.<br>
<div class="HOEnZb"><div class="h5"><br>
-- Scott<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br>
</div></div></blockquote></div><br></div>