Skip to Content.
Sympa Menu

metadata-support - Re: [Metadata-Support] How to test the per-entity metadata server from an IDP

Subject: InCommon metadata support

List archive

Re: [Metadata-Support] How to test the per-entity metadata server from an IDP


Chronological Thread 
  • From: "Cantor, Scott" <>
  • To: "" <>
  • Subject: Re: [Metadata-Support] How to test the per-entity metadata server from an IDP
  • Date: Wed, 2 Mar 2016 21:42:15 +0000
  • Accept-language: en-US
  • Authentication-results: spf=pass (sender IP is 164.107.81.218) smtp.mailfrom=osu.edu; incommon.org; dkim=none (message not signed) header.d=none;incommon.org; dmarc=bestguesspass action=none header.from=osu.edu;
  • Spamdiagnosticmetadata: NSPM
  • Spamdiagnosticoutput: 1:23

On 3/2/16, 4:13 PM,
"
on behalf of Tom Scavo"
<
on behalf of
>
wrote:


>
>Yes, I did understand your point, but the main reason I pushed back is
>that the above strategy may not be the best strategy---heck, it may
>not even be a good strategy---so I think we need to step back and take
>stock. (Btw, you're not the first one to contemplate such a
>configuration, so you're in good company :)

I can't really imagine any other way to put it under some stress without
risk. Assuming appropriate timeouts, it's got to be fairly reasonable.

>When in doubt, do what Scott does :-) That is, identify one or more
>SPs under your control (as SP owner, not Site Administrator) that will
>tolerate a switch to mdq-beta. I'll let Scott describe what he does on
>shibboleth.net (although I think he may have already let the cat out
>of the bag).

Well, SP's are harder if they need discovery, since you're stuck loading the
aggregate regardless, but the logs don't suggest we've had any trouble with
using the MDQ server as the primary for metadata lookup.

-- Scott




Archive powered by MHonArc 2.6.16.

Top of Page