<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=Windows-1252">
<style type="text/css" style="display:none;"><!-- P {margin-top:0;margin-bottom:0;} --></style>
</head>
<body dir="ltr">
<div id="divtagdefaultwrapper" style="font-size:11pt;color:#000000;font-family:Calibri,Helvetica,sans-serif;" dir="ltr">
<p style="margin-top:0;margin-bottom:0">While this isn't the underlying cause here, another issue in the December time frame was that InCommon failed over
<a href="http://md.incommon.org/" class="OWAAutoLink" id="LPlnk565864" previewremoved="true">
http://md.incommon.org/</a> from the Michigan server (207.75.165.125) to the Los Angeles server (<span>163.253.32.9</span>) between at least 12/13/2017 and 12/27/2017.</p>
<p style="margin-top:0;margin-bottom:0"><br>
</p>
<p style="margin-top:0;margin-bottom:0">We'd sent our campus SP users a number of notices about the (potential) need for an additional firewall rule back in August 2017, but sure enough, we started receiving reports from a few campus SPs who had ignored the
 memo and were experiencing failed logins in late December.</p>
<p style="margin-top:0;margin-bottom:0"><br>
</p>
<p style="margin-top:0;margin-bottom:0">Michael<br>
</p>
</div>
<hr style="display:inline-block;width:98%" tabindex="-1">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Cantor, Scott <cantor.2@osu.edu><br>
<b>Sent:</b> Thursday, January 4, 2018 1:15:44 PM<br>
<b>To:</b> Shib Users<br>
<b>Subject:</b> Re: outage due to not downloading incommon metadata</font>
<div> </div>
</div>
<div class="BodyFragment"><font size="2"><span style="font-size:11pt;">
<div class="PlainText">On 1/4/18, 2:06 PM, "users on behalf of Hyzer, Chris" <users-bounces@shibboleth.net on behalf of mchyzer@isc.upenn.edu> wrote:<br>
<br>
> QUESTION 1: Any idea why some servers are downloading and some aren’t? <br>
<br>
Some are fully patched and some are running the broken xmltooling pushed out with the original 2.6 patch.<br>
<br>
> QUESTION 2: Should I be bouncing shibd weekly?<br>
<br>
No.<br>
<br>
> QUESTION 3: I didn’t have the /Status handler hooked up, so it took a user report to find out about this.  Would the
<br>
> /Status return a 500 and Nagios would tell me or do I need to look at the results for an <OK/>?<br>
<br>
Simply monitoring with a login is the usual complete answer but otherwise if the status dump includes the dates associated with the metadata, it's probably worth something to look at it.<br>
<br>
 > Bouncing the SP fixed this issue for now.<br>
<br>
It won't stay fixed if it's not patched.<br>
<br>
> QUESTION 4: This was logged as a WARN, should it be an error?<br>
<br>
No...<br>
<br>
> <a href="https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPLogging">
https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPLogging</a><br>
>“WARN: Indicates something that's noteworthy, but not an actual error.<br>
> ERROR: Something's wrong. Users are likely to be affected any time one appears.”<br>
<br>
That is not at all consistent with the the levels as they're used, so I'll have to change the text.<br>
 <br>
-- Scott<br>
<br>
<br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg">
https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net</div>
</span></font></div>
</body>
</html>