<div dir="ltr"><div>The SignatureValidation issue is resolved, no error. I left out the validUntil.</div><div><br></div><div> <MetadataProvider id="incommon"<br> xsi:type="FileBackedHTTPMetadataProvider"<br> backingFile="%{idp.home}/metadata/incommon-metadata.xml"<br> metadataURL="<a href="http://md.incommon.org/InCommon/InCommon-metadata.xml" target="_blank">http://md.incommon.org/InCommon/InCommon-metadata.xml</a>"> <br> <br> <MetadataFilter xsi:type="SignatureValidation" certificateFile="%{idp.home}/credentials/inc-md-cert.pem" /><br> <MetadataFilter xsi:type="RequiredValidUntil" maxValidityInterval="P30D"/><br> </MetadataProvider><br></div><div><br></div><div>But as par for the course I have another error and its for the very end of the metadata-providers.xml file. Its well formed and valid. I am not sure what to check.</div><div><br></div><div>2019-11-27 14:39:58,147 - - INFO [net.shibboleth.utilities.java.support.service.AbstractReloadableService:173] - Service 'shibboleth.MetadataResolverService': Performing initial load<br>2019-11-27 14:39:58,147 - - INFO [net.shibboleth.utilities.java.support.service.AbstractReloadableService:258] - Service 'shibboleth.MetadataResolverService': Reloading service configuration<br>2019-11-27 14:39:58,149 - - INFO [net.shibboleth.ext.spring.util.SchemaTypeAwareXMLBeanDefinitionReader:317] - Loading XML bean definitions from file [/opt/shibboleth-idp/conf/metadata-providers.xml]<br>2019-11-27 14:39:58,208 - - ERROR [net.shibboleth.utilities.java.support.service.AbstractReloadableService:182] - Service 'shibboleth.MetadataResolverService': Initial load failed<br>net.shibboleth.utilities.java.support.service.ServiceException: org.springframework.beans.factory.xml.XmlBeanDefinitionStoreException: Line 332 in XML document from file [/opt/shibboleth-idp/conf/metadata-providers.xml] is invalid; nested exception is org.xml.sax.SAXParseException; lineNumber: 332; columnNumber: 20; cvc-complex-type.2.3: Element 'MetadataProvider' cannot have character [children], because the type's content type is element-only.<br> at net.shibboleth.ext.spring.service.ReloadableSpringService.doReload(ReloadableSpringService.java:377)<br>Caused by: org.springframework.beans.factory.xml.XmlBeanDefinitionStoreException: Line 332 in XML document from file [/opt/shibboleth-idp/conf/metadata-providers.xml] is invalid; nested exception is org.xml.sax.SAXParseException; lineNumber: 332; columnNumber: 20; cvc-complex-type.2.3: Element 'MetadataProvider' cannot have character [children], because the type's content type is element-only.<br> at org.springframework.beans.factory.xml.XmlBeanDefinitionReader.doLoadBeanDefinitions(XmlBeanDefinitionReader.java:399)<br>Caused by: org.xml.sax.SAXParseException: cvc-complex-type.2.3: Element 'MetadataProvider' cannot have character [children], because the type's content type is element-only.<br> at com.sun.org.apache.xerces.internal.util.ErrorHandlerWrapper.createSAXParseException(ErrorHandlerWrapper.java:203)<br></div><div><br></div><br clear="all"><div><div dir="ltr" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div dir="ltr"><div dir="ltr"><div>Scott Gilbert</div><div>IAM System Admin</div><div>ETS Enterprise Technology Services</div><div>University of California Santa Barbara</div><div><br></div></div></div></div></div></div></div></div><br></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Wed, Nov 27, 2019 at 11:39 AM Scott Gilbert <<a href="mailto:sgilbert@ucsb.edu" target="_blank">sgilbert@ucsb.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="ltr">The previous sysadmin got the shib service to run without the incommon validation cert, and just the url for the incommon metadata is in metadata-providers.xml. I was suprised to discover this as I diagnosed this error.<br><br>shib 3.2.1 working service<br>tomcat-8.0.24<br>java version "1.8.0_51"<br>Java(TM) SE Runtime Environment (build 1.8.0_51-b16)<br>Java HotSpot(TM) 64-Bit Server VM (build 25.51-b03, mixed mode)<br><br>New server shib 3.4.6<br>tomcat-9.0.26<br>openjdk version "1.8.0_222"<br>OpenJDK Runtime Environment (build 1.8.0_222-b10)<br>OpenJDK 64-Bit Server VM (build 25.222-b10, mixed mode)<br><div><div dir="ltr"><div dir="ltr"><div><div dir="ltr"><div dir="ltr"><div dir="ltr"><div><br></div><div><br></div><div>Scott Gilbert</div><div>IAM System Admin</div><div>ETS Enterprise Technology Services</div><div>University of California Santa Barbara</div><div><br></div></div></div></div></div></div></div></div><br></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Wed, Nov 27, 2019 at 10:51 AM Cantor, Scott <<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">On 11/27/19, 1:36 PM, "users on behalf of Scott Gilbert" <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a> on behalf of <a href="mailto:sgilbert@ucsb.edu" target="_blank">sgilbert@ucsb.edu</a>> wrote:<br>
<br>
> To back up a bit, this is a new tomcat server and shibboleth idp 3.4.6. I have copied the data over from an existing <br>
> (working) shibboleth idp 3.2.1. The data would include idp.property settings, metadata, and credentials. The entire <br>
> credentials directory.<br>
<br>
And the InCommon verification key file isn't the same. Or the original isn't/wasn't working to start with. Or there's a Java difference of an unknown nature.<br>
<br>
-- Scott<br>
<br>
<br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>
</blockquote></div>