<div dir="ltr">Ahh, thanks, I had not considered that. We aren't yet using any AttributeRegistry. I don't think any of that was populated as part of the upgrade process. Right now, if I try to reload the AttributeRegistry I get a 404, so I'll need to figure out how to get that working.</div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Fri, May 13, 2022 at 11:30 AM Tom Zeller <<a href="mailto:tzeller@dragonacea.biz">tzeller@dragonacea.biz</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-style:solid;border-left-color:rgb(204,204,204);padding-left:1ex"><div dir="auto"><div dir="ltr"></div><div dir="ltr">Reload the attribute registry too, for encoders.</div><div dir="ltr"><br></div><div dir="ltr">Tom</div><div dir="ltr"><br><blockquote type="cite">On May 13, 2022, at 3:41 PM, Baron Fujimoto <<a href="mailto:baron@hawaii.edu" target="_blank">baron@hawaii.edu</a>> wrote:<br><br></blockquote></div><blockquote type="cite"><div dir="ltr"><div dir="ltr">We're running IdP 4.2.1. For some reason, reloading AttributeResolverService on demand doesn't seem to be working. We have the following in services.xml:<div><br></div><div><font face="monospace">    <util:list id ="shibboleth.AttributeResolverResources"><br>        <value>%{idp.home}/conf/attribute-resolver.xml</value><br>        <!-- Custom activation conditions --><br>        <value>%{idp.home}/conf/activation-condition.xml</value><br>    </util:list></font></div><div><br></div><div>But if I update an attribute definition in attribute-resolver.xml (say something simple, like changing a friendlyName), then try to reload the AttributeResolverService with</div><div><br></div><div>curl -k 'https://${idp_host}/idp/profile/admin/reload-service?id=shibboleth.AttributeResolverService'<br clear="all"><div><br></div><div>I get the output, "Configuration reloaded for 'shibboleth.AttributeResolverService'" but it It has no effect and I don't see the change if I do a resolvertest for the updated attribute.</div><div><br></div><div>However, the update to attribute-resolver.xml does appear to take effect on the quarter hour, which seems to be consistent with "idp.service.attribute.resolver.checkInterval = PT15M" in services.properties</div><div><br></div><div>FWIW, AttributeFilterResources appears to work as expected when reloaded on demand.</div><div><br></div><div>Any suggestions as to what's wrong here, or how to further troubleshoot this?</div>-- <br><div dir="ltr"><div dir="ltr"><font face="arial, sans-serif">Baron Fujimoto <<a href="mailto:baron@hawaii.edu" target="_blank">baron@hawaii.edu</a>> ::: UH Information Technology Services<br>minutas cantorum, minutas balorum, minutas carboratum descendus pantorum</font></div></div></div></div>
<span>-- </span><br><span>For Consortium Member technical support, see <a href="https://shibboleth.atlassian.net/wiki/x/ZYEpPw" target="_blank">https://shibboleth.atlassian.net/wiki/x/ZYEpPw</a></span><br><span>To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a></span><br></div></blockquote></div>-- <br>
For Consortium Member technical support, see <a href="https://shibboleth.atlassian.net/wiki/x/ZYEpPw" rel="noreferrer" target="_blank">https://shibboleth.atlassian.net/wiki/x/ZYEpPw</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div><br clear="all"><div><br></div>-- <br><div dir="ltr" class="gmail_signature"><div dir="ltr"><font face="arial, sans-serif">Baron Fujimoto <<a href="mailto:baron@hawaii.edu" target="_blank">baron@hawaii.edu</a>> ::: UH Information Technology Services<br>minutas cantorum, minutas balorum, minutas carboratum descendus pantorum</font></div></div>