per-entity - Re: [Per-Entity] HTTPS transport and TLS trust
Subject: Per-Entity Metadata Working Group
List archive
- From: Nicholas Roy <>
- To: <>
- Subject: Re: [Per-Entity] HTTPS transport and TLS trust
- Date: Fri, 23 Sep 2016 10:05:50 -0600
- Authentication-results: spf=none (sender IP is ) ;
- Ironport-phdr: 9a23:728ikxcVguBOPCRubcdjKnyxlGMj4u6mDksu8pMizoh2WeGdxc28YR7h7PlgxGXEQZ/co6odzbGJ4+a9AidZvN6oizMrTt9lb1c9k8IYnggtUoauKHbQC7rUVRE8B9lIT1R//nu2YgB/Ecf6YEDO8DXptWZBUka3CQ0gcvz4AMvfidi2y/Ga+pvYZABNgzz7Zql9ekaYtwLU4+8XiotlLq8qgiHOszMcff5R1EtpI06ehRDx+p328ZJ+pXcD88k9/tJNBP2pN58zSqZVWWwr
- Spamdiagnosticmetadata: NSPM
- Spamdiagnosticoutput: 1:99
On 9/6/16 5:37 PM, Patrick Radtke wrote:
On Tue, Sep 6, 2016 at 4:24 PM, Tom Scavo
<>
wrote:
On Tue, Sep 6, 2016 at 7:19 PM, Cantor, ScottI believe a CDN will be cheaper than running a pair of EC2 instances
<>
wrote:
On 9/6/16 7:16 PM, Paul Caskey wrote:Well, our initial thought was to enable AWS Elastic Load Balancer for
To the extent that's true, then I would question the need for a CDN,I think the point of the CDN was not performance but in fact
as opposed to a normal highly-available infrastructure (which would be
less expensive to operate).
availability. I thought the issue was that InCommon wasn't comfortable
providing that HA infrastructure, at least enough that it was thought to
be worth investigating what a CDN would offer and cost.
automatic failover. It has not been tried, however, so I don't know if
it works as advertised.
and the ELB.
Cloud front is a penny per 10K HTTPS connections and ~9 cents for 10TB
of data transfer. There would probably be a dollar or two in S3
charges for storing the signed metadata. Going with servers, an ELB
and figuring out cross region HA will cost more than that.
To me the real advantage to the CDN is resilience to targeted attacks
against the MDQ servers. To me the largest downside is that failure
modes are now location specific, which can make it hard to provide an
accurate federation wide status of the service. If the cloudfront edge
in Toronto is having issues, who would it affect? how would they be
affected? would Ops be able to determine there was partial outage?,
etc, etc.
Exactly.
Nick
-Patrick
- Re: [Per-Entity] HTTPS transport and TLS trust, (continued)
- Re: [Per-Entity] HTTPS transport and TLS trust, Scott Koranda, 09/06/2016
- Re: [Per-Entity] HTTPS transport and TLS trust, Tom Scavo, 09/06/2016
- Re: [Per-Entity] HTTPS transport and TLS trust, Nicholas Roy, 09/23/2016
- RE: [Per-Entity] HTTPS transport and TLS trust, Paul Caskey, 09/06/2016
- Re: [Per-Entity] HTTPS transport and TLS trust, Cantor, Scott, 09/06/2016
- RE: [Per-Entity] HTTPS transport and TLS trust, Paul Caskey, 09/06/2016
- Re: [Per-Entity] HTTPS transport and TLS trust, Tom Scavo, 09/06/2016
- Re: [Per-Entity] HTTPS transport and TLS trust, Patrick Radtke, 09/06/2016
- Re: [Per-Entity] HTTPS transport and TLS trust, Scott Koranda, 09/06/2016
- RE: [Per-Entity] HTTPS transport and TLS trust, Paul Caskey, 09/07/2016
- Re: [Per-Entity] HTTPS transport and TLS trust, Nicholas Roy, 09/23/2016
- Re: [Per-Entity] HTTPS transport and TLS trust, Scott Koranda, 09/06/2016
- RE: [Per-Entity] HTTPS transport and TLS trust, Paul Caskey, 09/07/2016
- RE: [Per-Entity] HTTPS transport and TLS trust, Paul Caskey, 09/06/2016
- Re: [Per-Entity] HTTPS transport and TLS trust, Cantor, Scott, 09/23/2016
- Re: [Per-Entity] HTTPS transport and TLS trust, Nicholas Roy, 09/23/2016
Archive powered by MHonArc 2.6.19.