<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:Helvetica;
        panose-1:2 11 6 4 2 2 2 2 2 4;}
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Aptos;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        font-size:12.0pt;
        font-family:"Aptos",sans-serif;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
span.EmailStyle18
        {mso-style-type:personal-reply;
        font-family:"Aptos",sans-serif;
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="blue" vlink="purple" style="word-wrap:break-word">
<div class="WordSection1">
<p class="MsoNormal">Thanks, all. Pete was correct. As long as I’ve been working with systemd, I still keep discovering things about it that I didn’t know. I had no idea it did sandboxing of services.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">By adding two ReadWritePaths directives to the [service] block of the Tomcat 10 unit override, one for the logs dir and one for the downloaded metadata dir, we got the IdP to start logging. It’s still throwing a servlet exception, but now
 that we have logs, we should be able to figure out why.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Keith<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif">From:</span></b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif"> Pete Birkinshaw <pete@digitalidentitylabs.com>
<br>
<b>Sent:</b> Tuesday, January 21, 2025 11:16 AM<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Cc:</b> Wessel, Keith <kwessel@illinois.edu><br>
<b>Subject:</b> Re: IdP 5 not accessible after upgrade on a Ubuntu server<o:p></o:p></span></p>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<div id="bloop_customfont">
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Helvetica",sans-serif"><o:p> </o:p></span></p>
</div>
<div id="bloop_customfont">
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Helvetica",sans-serif">It would be worth checking systemd's sandboxing too - it can also limit access to filesystem directories.<o:p></o:p></span></p>
</div>
<div id="bloop_customfont">
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Helvetica",sans-serif"><o:p> </o:p></span></p>
</div>
<div id="bloop_customfont">
<p class="MsoNormal"><span style="font-size:10.0pt;font-family:"Helvetica",sans-serif">Pete<o:p></o:p></span></p>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<div id="bloop_sign_1737479324235401984">
<p class="MsoNormal"><span style="font-size:10.5pt;font-family:"Helvetica",sans-serif">-- <br>
Pete Birkinshaw<br>
Digital Identity Ltd | </span><a href="https://urldefense.com/v3/__http:/www.digitalidentity.ltd.uk/__;!!DZ3fjg!6rXrHzIWSwXdEnz6NXzeEXeQm-oiwpqsE_B-_vFHMKLI3qManOEKBVxcWFER5q-kzJLFEUkBTHZ5nvPSl5hX20m4$"><span style="font-size:10.5pt;font-family:"Helvetica",sans-serif">http://www.digitalidentity.ltd.uk</span></a><span style="font-size:10.5pt;font-family:"Helvetica",sans-serif"> <br>
Registered in England and Wales No. 7121888 </span><o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><span style="color:black"><br>
From: Wessel, Keith via users <a href="mailto:users@shibboleth.net"><users@shibboleth.net></a><br>
Reply: Shib Users <a href="mailto:users@shibboleth.net"><users@shibboleth.net></a><br>
Date: 21 January 2025 at 16:54:58<br>
To: users@shibboleth.net <a href="mailto:users@shibboleth.net"><users@shibboleth.net></a><br>
Cc: Wessel, Keith <a href="mailto:kwessel@illinois.edu"><kwessel@illinois.edu></a><br>
Subject:  IdP 5 not accessible after upgrade on a Ubuntu server <o:p></o:p></span></p>
</div>
<p class="MsoNormal"><br>
<br>
<o:p></o:p></p>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<div>
<div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto">Hi, all,<o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"> <o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto">I’m rather stumped here and am hoping for some direction of where to look next.<o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"> <o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto">I’m helping another campus upgrade from IdP 4 to IdP 5. They’re running on a Ubuntu server that they upgraded from 22.04 to 24.04 to get access to Tomcat 10. They also upgraded
 from Tomcat 9 to 10 and Java 8 to 17.<o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"> <o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto">Tomcat’s starting, and it’s deploying the IdP. This from Catalina.out:<o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><o:p> </o:p></p>
</div>
</div>
</div>
</blockquote>
</div>
</body>
</html>