<html><body><div style="font-family: courier new,courier,monaco,monospace,sans-serif; font-size: 10pt; color: #000000"><div>Hi Russel,<br></div><div><br data-mce-bogus="1"></div><div>There is no tool scanning the logs. The tmp files content cannot be found in the regular log files.<br data-mce-bogus="1"></div><div>It might be related to log4j, I found some bugs like this one on logback jira site.<br data-mce-bogus="1"></div><div>To mitigate the problem I have written a script that adds the tmp files content to the regular logs, restarts tomcat, and run it a 0h05.<br data-mce-bogus="1"></div><div><br data-mce-bogus="1"></div><div>Tegards,<br data-mce-bogus="1"></div><div><br data-mce-bogus="1"></div><div><br></div><div data-marker="__SIG_PRE__">Vincent Delhommeau <br>Administrateur Systèmes & Réseaux <br>EHESS - DSI/SERI <br>01 49 54 84 46 <br></div><div><br></div><hr id="zwchr" data-marker="__DIVIDER__"><div data-marker="__HEADERS__"><b>De: </b>"Russell Beall" <beall@usc.edu><br><b>À: </b>"Shib Users" <users@shibboleth.net><br><b>Envoyé: </b>Mardi 21 Avril 2020 19:09:25<br><b>Objet: </b>Re: problem with IdP log files<br></div><div><br></div><div data-marker="__QUOTED_TEXT__">I’ve seen this issue occur when the logs are scanned by a tool which is using gunzip -c to decrypt the log files in place.  If the gunzip process is interrupted, it leaves those tmp files around.  This is separate from the IdP and is not likely caused by log rolling or something within tomcat.<div class="">Regards,</div><div class="">Russ.<br class=""><div class=""><div dir="auto" style="color: #000000; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class="" data-mce-style="color: #000000; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;"><div dir="auto" style="color: #000000; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class="" data-mce-style="color: #000000; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;"><div style="color: #000000; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class="" data-mce-style="color: #000000; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;"><div class=""><div class=""><div style="orphans: 2; widows: 2; margin: 0px;" class="" data-mce-style="orphans: 2; widows: 2; margin: 0px;"><div style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class="" data-mce-style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;"><div style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class="" data-mce-style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;"><div class=""><div style="margin: 0px;" class="" data-mce-style="margin: 0px;"><div style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class="" data-mce-style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;"><div style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class="" data-mce-style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;"><div class=""><div style="margin: 0px;" class="" data-mce-style="margin: 0px;"><div dir="auto" style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class="" data-mce-style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;"><div style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class="" data-mce-style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;"><div style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class="" data-mce-style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;"><div class=""><div style="margin: 0px;" class="" data-mce-style="margin: 0px;">=========================</div><div style="margin: 0px;" class="" data-mce-style="margin: 0px;"><b class="">Russell Beall  |  Identity and Access Management Lead Engineer</b></div><div style="margin: 0px;" class="" data-mce-style="margin: 0px;">Office of the CISO | <span data-mce-style="color: #991b1e;" style="color: #991b1e;" color="#991b1e">University of Southern California</span> </div><div style="margin: 0px;" class="" data-mce-style="margin: 0px;">(213) 740-7221  |  <a href="mailto:beall@usc.edu" class="" target="_blank" data-mce-href="mailto:beall@usc.edu">beall@usc.edu</a><br data-mce-bogus="1"></div><div class=""><br class=""></div></div><div class=""><br class=""></div></div></div><br class="Apple-interchange-newline"></div><br class="Apple-interchange-newline"></div></div></div></div></div></div></div></div></div></div></div></div></div></div><br class="Apple-interchange-newline"></div><div><br class=""><blockquote class=""><div class="">On Apr 21, 2020, at 5:32 AM, Delhommeau Vincent <<a href="mailto:vincent.delhommeau@ehess.fr" class="" target="_blank" data-mce-href="mailto:vincent.delhommeau@ehess.fr">vincent.delhommeau@ehess.fr</a>> wrote:</div><br class="Apple-interchange-newline"><div class=""><div class=""><div style="font-family: 'courier new', courier, monaco, monospace, sans-serif; font-size: 10pt;" class="" data-mce-style="font-family: 'courier new', courier, monaco, monospace, sans-serif; font-size: 10pt;"><div class="">I forgot to mention that if I restart tomcat, it will stop writing in the tmp files.<br class=""></div><div class="">Could it be a bug in log4j ?<br class=""></div><div class=""><br class=""></div><div class="">Vincent Delhommeau <br class=""> Administrateur Systèmes & Réseaux <br class=""> EHESS - DSI/SERI <br class=""> 01 49 54 84 46 <br class=""></div><br class=""><hr id="zwchr" class=""><div class=""><b class="">De: </b>"Delhommeau Vincent" <<a href="mailto:vincent.delhommeau@ehess.fr" class="" target="_blank" data-mce-href="mailto:vincent.delhommeau@ehess.fr">vincent.delhommeau@ehess.fr</a>><br class=""> <b class="">À: </b><a href="mailto:users@shibboleth.net" class="" target="_blank" data-mce-href="mailto:users@shibboleth.net">users@shibboleth.net</a><br class=""> <b class="">Envoyé: </b>Lundi 20 Avril 2020 17:34:59<br class=""> <b class="">Objet: </b>problem with IdP log files<br class=""></div><br class=""><div class=""><div style="font-family: 'courier new', courier, monaco, monospace, sans-serif; font-size: 10pt;" class="" data-mce-style="font-family: 'courier new', courier, monaco, monospace, sans-serif; font-size: 10pt;"><div class="">Hi,<br class=""></div><br class=""><div class="">I'm finishing the setup of a shibboleth v 3.4.4 IdP.<br class=""></div><div class="">I have found strange files in the logs folder.<br class=""></div><div class="">Here is a partial litsting of /opt/shibboleth-idp/logs :<br class=""></div><br class=""><div class="">-rw-r--r--  1 tomcat tomcat  21583 Apr 18 00:00 idp-process-2020-04-17.log.gz<br class=""> -rw-r--r--  1 tomcat tomcat   4770 Apr 18 00:03 idp-process-2020-04-17.log713182882606029.tmp<br class=""> -rw-r--r--  1 tomcat tomcat   2862 Apr 18 00:00 idp-process-2020-04-17.log713194143509376.tmp<br class=""> -rw-r--r--  1 tomcat tomcat  11957 Apr 19 00:00 idp-process-2020-04-18.log.gz<br class=""> -rw-r--r--  1 tomcat tomcat    954 Apr 19 00:00 idp-process-2020-04-18.log799578327391671.tmp<br class=""> -rw-r--r--  1 tomcat tomcat    954 Apr 19 00:00 idp-process-2020-04-18.log799588595404227.tmp<br class=""> -rw-r--r--  1 tomcat tomcat  11916 Apr 20 00:00 idp-process-2020-04-19.log.gz<br class=""> -rw-r--r--  1 tomcat tomcat    954 Apr 20 00:00 idp-process-2020-04-19.log885979225206155.tmp<br class=""> -rw-r--r--  1 tomcat tomcat    954 Apr 20 00:00 idp-process-2020-04-19.log885988711505334.tmp<br class=""> -rw-r--r--  1 tomcat tomcat 165221 Apr 20 16:40 idp-process.log<br class=""> -rw-r--r--  1 tomcat tomcat   2122 Apr 18 00:00 idp-warn-2020-04-17.log.gz<br class=""> -rw-r--r--  1 tomcat tomcat   4770 Apr 18 00:03 idp-warn-2020-04-17.log713182892530877.tmp<br class=""> -rw-r--r--  1 tomcat tomcat   2862 Apr 18 00:00 idp-warn-2020-04-17.log713194148379693.tmp<br class=""> -rw-r--r--  1 tomcat tomcat    861 Apr 19 00:00 idp-warn-2020-04-18.log.gz<br class=""> -rw-r--r--  1 tomcat tomcat    954 Apr 19 00:00 idp-warn-2020-04-18.log799578331483925.tmp<br class=""> -rw-r--r--  1 tomcat tomcat    954 Apr 19 00:00 idp-warn-2020-04-18.log799588599983199.tmp<br class=""> -rw-r--r--  1 tomcat tomcat    820 Apr 20 00:00 idp-warn-2020-04-19.log.gz<br class=""> -rw-r--r--  1 tomcat tomcat    954 Apr 20 00:00 idp-warn-2020-04-19.log885979229538330.tmp<br class=""> -rw-r--r--  1 tomcat tomcat    954 Apr 20 00:00 idp-warn-2020-04-19.log885988715547676.tmp<br class=""> -rw-r--r--  1 tomcat tomcat   5972 Apr 20 09:10 idp-warn.log</div><br class=""><div class="">After log rotation shibboleth writes in temporary files along with the regular log files.<br class=""></div><div class="">The problem only concerns idp-process.log and idp-warn.log, the other log files are "normal".<br class=""></div><div class="">I didnt change the logging settings.<br class=""></div><br class=""><div class="">Two monthes ago I tried to install v 3.4.6 IdP. I dropped it because I could not make the shibcas plugin work, but kept the installation folder.<br class=""></div><div class="">I can see the same behaviour with log files.<br class=""></div><br class=""><div class="">Has someone already met this situation ?<br class=""></div><br class=""><div class="">My configuration : opensuse leap 15.1, apache 2.4.33, tomcat 9.0.31, java 1.8.0.242 openjdk<br class=""></div><br class=""><div class="">Regards,<br class=""></div><br class=""><div class="">Vincent Delhommeau <br class=""> Administrateur Systèmes & Réseaux <br class=""> EHESS - DSI/SERI <br class=""> 01 49 54 84 46 <br class=""></div></div><br class=""> -- <br class=""> For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" class="" target="_blank" data-mce-href="https://wiki.shibboleth.net/confluence/x/coFAAg"> https://wiki.shibboleth.net/confluence/x/coFAAg</a><br class=""> To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" class="" target="_blank" data-mce-href="mailto:users-unsubscribe@shibboleth.net"> users-unsubscribe@shibboleth.net</a><br class=""></div></div></div>-- <br class=""> For Consortium Member technical support, see <a href="https://urldefense.com/v3/__https://wiki.shibboleth.net/confluence/x/coFAAg__;!!LIr3w8kk_Xxm!8z58Ng31x3-Ok82D2jkpRhrpoOHybFLAdlJ58Z9EVGDpnhtIotY1co5D5Tu7$" class="" target="_blank" data-mce-href="https://urldefense.com/v3/__https://wiki.shibboleth.net/confluence/x/coFAAg__;!!LIr3w8kk_Xxm!8z58Ng31x3-Ok82D2jkpRhrpoOHybFLAdlJ58Z9EVGDpnhtIotY1co5D5Tu7$"> https://urldefense.com/v3/__https://wiki.shibboleth.net/confluence/x/coFAAg__;!!LIr3w8kk_Xxm!8z58Ng31x3-Ok82D2jkpRhrpoOHybFLAdlJ58Z9EVGDpnhtIotY1co5D5Tu7$</a> <br class=""> To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" class="" target="_blank" data-mce-href="mailto:users-unsubscribe@shibboleth.net"> users-unsubscribe@shibboleth.net</a><br data-mce-bogus="1"></div></blockquote></div><br class=""></div><br>-- <br>For Consortium Member technical support, see https://wiki.shibboleth.net/confluence/x/coFAAg<br>To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br></div></div></body></html>