<div dir="ltr">Aha, I had indeed missed that - thanks!<div><br></div><div>For the record, </div><div><a href="https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/1265631657/MetadataProviderCommonAttributes" target="_blank">https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/1265631657/MetadataProviderCommonAttributes</a> shows that failFastInitialization defaults to true for a FileBackedHTTPMetadataProvider.</div><div><br></div><div>Setting failFastInitialization="false" on the MetadataProvider then causes the IdP to log this at startup and the MetadataResolver initialises "successfully":</div><div><br></div><div>ERROR [org.opensaml.saml.metadata.resolver.impl.AbstractMetadataResolver:296] [ ] - Metadata Resolver FileBackedHTTPMetadataResolver foobar: Metadata provider failed to properly initialize, fail-fast=false, continuing on in a degraded state<br></div><div><br></div><div>Thanks,</div><div><br></div><div>Max</div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Tue, 20 Jul 2021 at 13:00, Cantor, Scott <<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">If the service had been failfast the IdP wouldn't have started, so it's working exactly as intended. I imagine you are also ignoring the fact that each individual resolver has its own fail fast settings.<br>
<br>
-- Scott<br>
<br>
<br>
</blockquote></div><br clear="all"><div><br></div>-- <br><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div style="font-size:small">Max Spicer - Identity Systems Developer</div><div style="font-size:small">IT Services, University of York<br></div></div></div></div></div></div>