<div dir="ltr">The previous sysadmin got the shib service to run without the incommon validation cert, and just the url for the incommon metadata is in metadata-providers.xml. I was suprised to discover this as I diagnosed this error.<br><br>shib 3.2.1 working service<br>tomcat-8.0.24<br>java version "1.8.0_51"<br>Java(TM) SE Runtime Environment (build 1.8.0_51-b16)<br>Java HotSpot(TM) 64-Bit Server VM (build 25.51-b03, mixed mode)<br><br>New server shib 3.4.6<br>tomcat-9.0.26<br>openjdk version "1.8.0_222"<br>OpenJDK Runtime Environment (build 1.8.0_222-b10)<br>OpenJDK 64-Bit Server VM (build 25.222-b10, mixed mode)<br><div><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div dir="ltr"><div dir="ltr"><div><br></div><div><br></div><div>Scott Gilbert</div><div>IAM System Admin</div><div>ETS Enterprise Technology Services</div><div>University of California Santa Barbara</div><div><br></div></div></div></div></div></div></div></div><br></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Wed, Nov 27, 2019 at 10:51 AM Cantor, Scott <<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">On 11/27/19, 1:36 PM, "users on behalf of Scott Gilbert" <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a> on behalf of <a href="mailto:sgilbert@ucsb.edu" target="_blank">sgilbert@ucsb.edu</a>> wrote:<br>
<br>
> To back up a bit, this is a new tomcat server and shibboleth idp 3.4.6. I have copied the data over from an existing <br>
> (working) shibboleth idp 3.2.1. The data would include idp.property settings, metadata, and credentials. The entire <br>
> credentials directory.<br>
<br>
And the InCommon verification key file isn't the same. Or the original isn't/wasn't working to start with. Or there's a Java difference of an unknown nature.<br>
<br>
-- Scott<br>
<br>
<br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>