<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class="elementToProof ContentPasted0">
Issue:
<div class="ContentPasted0"> Shibboleth failed to boot. Jetty log presented this message.
</div>
<div class="ContentPasted0">================================================================</div>
<div class="ContentPasted0">WARN [org.eclipse.jetty.webapp.WebAppContext:533] - Failed startup of context o.e.j.w.WebAppContext@305a0c5f{Shibboleth Identity Pr</div>
<div class="ContentPasted0">ovider,/idp,[file:///opt/jetty/temp/jetty-127_0_0_1-8008-idp_war-_idp-any-11747669412705206324/webinf/, jar:file:///opt/shibboleth-idp/war/idp.war!/],UNAVAIL</div>
<div class="ContentPasted0">ABLE}{/opt/shibboleth-idp/war/idp.war}</div>
<div class="ContentPasted0">org.springframework.beans.factory.BeanDefinitionStoreException: Invalid bean definition with name 'shibboleth.AvailableAuthenticationFlows' defined in null:</div>
<div class="ContentPasted0">Could not resolve placeholder 'idp.authn.DuoOIDC.subjectDecorator' in value "#{getObject('%{idp.authn.DuoOIDC.subjectDecorator}'.trim())}"; nested exception</div>
<div class="ContentPasted0">is java.lang.IllegalArgumentException: Could not resolve placeholder 'idp.authn.DuoOIDC.subjectDecorator' in value "#{getObject('%{idp.authn.DuoOIDC.subjectD</div>
<div class="ContentPasted0">ecorator}'.trim())}".......</div>
<div><br class="ContentPasted0">
</div>
<div class="ContentPasted0">Caused by: java.lang.IllegalArgumentException: Could not resolve placeholder 'idp.authn.DuoOIDC.subjectDecorator' in value "#{getObject('%{idp.authn.DuoOIDC.subjectDecorator}'.trim())}"</div>
<div class="ContentPasted0">================================================================</div>
<div><br class="ContentPasted0">
</div>
<div class="ContentPasted0">System versioning history: v3.3.3 -> v3.4.7 -> v3.4.8 -> v4.0.1(starting version) -> v4.1.0</div>
<div><br class="ContentPasted0">
</div>
<div class="ContentPasted0">Plugin installed: </div>
<div class="ContentPasted0">bin]# ./plugin.sh -l</div>
<div class="ContentPasted0">Plugin: net.shibboleth.oidc.common Current Version: 1.1.0</div>
<div class="ContentPasted0">Plugin: net.shibboleth.idp.plugin.authn.duo.nimbus Current Version: 1.0.0</div>
<div><br class="ContentPasted0">
</div>
<div class="ContentPasted0">Module states: </div>
<div class="ContentPasted0">bin]# ./module.sh -l</div>
<div class="ContentPasted0">Module: idp.oidc.common.1 [ENABLED] <=== this is enabled after I installed it ..</div>
<div class="ContentPasted0">Module: idp.authn.DuoOIDC [ENABLED] <=== this is enabled after I installed it ..</div>
<div class="ContentPasted0">Module: idp.authn.Duo [ENABLED]</div>
<div class="ContentPasted0">Module: idp.authn.External [ENABLED]</div>
<div class="ContentPasted0">Module: idp.authn.Function [ENABLED]</div>
<div class="ContentPasted0">Module: idp.authn.IPAddress [ENABLED]</div>
<div class="ContentPasted0">Module: idp.authn.MFA [ENABLED]</div>
<div class="ContentPasted0">Module: idp.authn.Password [ENABLED]</div>
<div class="ContentPasted0">Module: idp.authn.RemoteUser [ENABLED]</div>
<div class="ContentPasted0">Module: idp.authn.RemoteUserInternal [ENABLED]</div>
<div class="ContentPasted0">Module: idp.authn.SPNEGO [ENABLED]</div>
<div class="ContentPasted0">Module: idp.authn.X509 [DISABLED]</div>
<div class="ContentPasted0">Module: idp.authn.Demo [DISABLED]</div>
<div class="ContentPasted0">Module: idp.admin.Hello [DISABLED]</div>
<div class="ContentPasted0">Module: idp.admin.UnlockKeys [ENABLED]</div>
<div class="ContentPasted0">Module: idp.intercept.Consent [ENABLED]</div>
<div class="ContentPasted0">Module: idp.intercept.ContextCheck [ENABLED]</div>
<div class="ContentPasted0">Module: idp.intercept.ExpiringPassword [ENABLED]</div>
<div class="ContentPasted0">Module: idp.intercept.Impersonate [ENABLED]</div>
<div class="ContentPasted0">Module: idp.intercept.Warning [DISABLED]</div>
<div class="ContentPasted0">Module: idp.profile.CAS [ENABLED]</div>
<div><br class="ContentPasted0">
</div>
<div class="ContentPasted0">Jetty version: 9.4.35.v20201120</div>
<div><br class="ContentPasted0">
</div>
<div class="ContentPasted0">Java version: </div>
<div class="ContentPasted0">jetty]# java -version</div>
<div class="ContentPasted0">openjdk version "11.0.14.1" 2022-02-08 LTS</div>
<div class="ContentPasted0">OpenJDK Runtime Environment 18.9 (build 11.0.14.1+1-LTS)</div>
<div class="ContentPasted0">OpenJDK 64-Bit Server VM 18.9 (build 11.0.14.1+1-LTS, mixed mode, sharing)</div>
<div><br class="ContentPasted0">
</div>
<div class="ContentPasted0">Steps followed: </div>
<div class="ContentPasted0"> https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/1265631513/Upgrading</div>
<div class="ContentPasted0"> https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/1374027959/DuoOIDCAuthnConfiguration</div>
<div><br class="ContentPasted0">
</div>
<div class="ContentPasted0">authn/DuoOIDC Flow Descriptor XML is added in conf/authn/general-authn.xml --> https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/1374027959/DuoOIDCAuthnConfiguration#General-Configuration</div>
<div><br class="ContentPasted0">
</div>
<div><br class="ContentPasted0">
</div>
<div class="ContentPasted0">Working workaround(which allows Jetty to boot properly and Shibboleth v4.1.0 working):
</div>
<div><br class="ContentPasted0">
</div>
<div class="ContentPasted0">Manual removal of this line in "Flow Descriptor XML" </div>
<div class="ContentPasted0">p:subjectDecorator-ref="#{getObject('%{idp.authn.DuoOIDC.subjectDecorator}'.trim())}"</div>
<div><br class="ContentPasted0">
</div>
<div class="ContentPasted0">Other attempts:</div>
<div><br class="ContentPasted0">
</div>
<div class="ContentPasted0">I have tried performing this upgrade path: v4.0.1-> v4.1.0 -> v4.3.1.
</div>
<div class="ContentPasted0">with v4.3.1 in place, I add both "oidc.common" and "duo.nimbus" plugins to its latest release version.
</div>
<div><br class="ContentPasted0">
</div>
<div class="ContentPasted0">I got the same result. </div>
<div><br class="ContentPasted0">
</div>
<div class="ContentPasted0">Questions: </div>
<div><br class="ContentPasted0">
</div>
<div class="ContentPasted0">is this a known issue for an upgraded Shib system ? </div>
<div class="ContentPasted0">Would the workaround post any issue with DuoOIDC functionalities ?
</div>
<div class="ContentPasted0">What am I missing from the upgrade process ? user error ?
</div>
<div><br class="ContentPasted0">
</div>
<div><br class="ContentPasted0">
</div>
Thank you for your time !</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class="elementToProof ContentPasted0">
<br>
</div>
<div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div id="Signature">
<div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);" data-ogsc="rgb(0, 0, 0)" data-ogsb="rgb(255, 255, 255)">
<span style="background-color: rgb(255, 255, 255);" data-ogsc="rgb(0, 0, 0)" data-ogsb="rgb(255, 255, 255)"><span style="background-color: rgb(255, 255, 255);" data-ogsb="rgb(255, 255, 255)">Chuck Yang<br>
</span></span>
<div>
<div data-ogsc="rgb(0, 0, 0)"><br>
</div>
<div>
<div>
<div style="background-color: rgb(255, 255, 255);" data-ogsc="rgb(0, 0, 0)" data-ogsb="rgb(255, 255, 255)">
<div>
<div>
<div><span>System Analyst, Infrastructure Services </span>
<div>Division of Information Technology</div>
<div><br>
</div>
<div>P: 657-278-5624 </div>
<div>800 N. State College Blvd. Fullerton, CA</div>
<span><a href="http://www.fullerton.edu/it" target="_blank" rel="noopener noreferrer" data-auth="NotApplicable" data-safelink="true" data-linkindex="0" data-ogsc="">http://www.fullerton.edu/it</a></span></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</body>
</html>