<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Exchange Server">
<!-- converted from text --><style><!-- .EmailQuote { margin-left: 1pt; padding-left: 4pt; border-left: #800000 2px solid; } --></style>
</head>
<body>
<meta content="text/html; charset=UTF-8">
<style type="text/css" style="">
<!--
p
        {margin-top:0;
        margin-bottom:0}
-->
</style>
<div dir="ltr">
<div id="x_divtagdefaultwrapper" dir="ltr" style="font-size:12pt; color:#000000; font-family:Calibri,Helvetica,sans-serif">
<p>Had this same problem crop up and was a problem for almost a month it seems, before the metadata actually expired.  Same deal though that restarting seems to have fixed it.  My best guess is that the version of java got updated by Linux updates and somehow
 that corrupted the cacerts file in some way?  But likewise not sure exactly what happened.</p>
<p><br>
</p>
<p><br>
</p>
</div>
<hr tabindex="-1" style="display:inline-block; width:98%">
<div id="x_divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" color="#000000" style="font-size:11pt"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Paul B. Henson <henson@cpp.edu><br>
<b>Sent:</b> Friday, December 3, 2021 3:27:07 PM<br>
<b>To:</b> Shib Users<br>
<b>Subject:</b> mdq download failure - trustAnchors parameter must be non-empty</font>
<div> </div>
</div>
</div>
<font size="2"><span style="font-size:10pt;">
<div class="PlainText">I received a few reports of "Unsupported Request" errors from users trying to access various services. It appeared there was a failure downloading the metadata via mdq:<br>
<br>
2021-12-03 10:30:22,111 - 2600:6c51:7c7f:760:b5d2:3497:da48:698d/node0ct4oh8f0w5dx1rsjwqiqgweku1932339 - ERROR [org.opensaml.saml.metadata.resolver.impl.AbstractDynamicMetadataResolver:869] - Metadata Resolver FunctionDrivenDynamicHTTPMetadataResolver incommon-mdq:
 Error fetching metadata from origin source<br>
javax.net.ssl.SSLException: Unexpected error: java.security.InvalidAlgorithmParameterException: the trustAnchors parameter must be non-empty<br>
        at java.base/sun.security.ssl.Alert.createSSLException(Alert.java:133)<br>
Caused by: java.lang.RuntimeException: Unexpected error: java.security.InvalidAlgorithmParameterException: the trustAnchors parameter must be non-empty<br>
        at java.base/sun.security.validator.PKIXValidator.<init>(PKIXValidator.java:102)<br>
Caused by: java.security.InvalidAlgorithmParameterException: the trustAnchors parameter must be non-empty<br>
        at java.base/java.security.cert.PKIXParameters.setTrustAnchors(PKIXParameters.java:200)<br>
<br>
The failures were sporadic and intermittent. The specific error seems to be generally associated with client configuration, but given it popped up out of the blue with no changes and was only happening on some requests that didn't seem likely. At first I thought
 there was a problem with Incommon's infrastructure, but then noticed that the errors were only occurring on one of my three nodes, which made that theory less likely.<br>
<br>
I ended up just restarting jetty on the problematic node and the problem seems to have gone away. My best guess is something got corrupted or into a bad state somewhere?<br>
<br>
Dunno, just throwing it out there for the archives, thanks...<br>
<br>
--<br>
Paul B. Henson  |  (909) 979-6361  |  <a href="http://www.cpp.edu/~henson/">http://www.cpp.edu/~henson/</a><br>
Operating Systems and Network Analyst  |  henson@cpp.edu<br>
California State Polytechnic University  |  Pomona CA 91768<br>
<br>
-- <br>
For Consortium Member technical support, see <a href="https://shibboleth.atlassian.net/wiki/x/ZYEpPw">
https://shibboleth.atlassian.net/wiki/x/ZYEpPw</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font>
</body>
</html>