<br><br><div class="gmail_quote">On Thu, Jan 5, 2012 at 8:55 AM, Peter Schober <span dir="ltr"><<a href="mailto:peter.schober@univie.ac.at">peter.schober@univie.ac.at</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
* McDermott, Michael <<a href="mailto:michael_mcdermott@brown.edu">michael_mcdermott@brown.edu</a>> <a href="tel:%5B2012-01-05%2014" value="+12012010514">[2012-01-05 14</a>:26]:<br>
<div class="im">> Attendant to that point, I saw this post this morning:<br>
> <a href="http://www.infoworld.com/t/application-servers/nginx-overtakes-microsoft-no-2-web-server-183079" target="_blank">http://www.infoworld.com/t/application-servers/nginx-overtakes-microsoft-no-2-web-server-183079</a><br>
><br>
> The headline is a bit sensational when you look at the statistics, but I<br>
> take the point that the market share for a third, high performance web<br>
> server, is growing to a level where it is probably mainstream.<br>
<br>
</div>I would also assume that these stats are likely to be skewed where<br>
Nginx is only used as a proxy/for static content (which is unlikely to<br>
be detected by Netcraft et al.).<br>
<br></blockquote><div>Hosting Static sites is something Apache is skewed toward. No one looks at an alternative web server unless Apache can't handle the situation and Apache is great at serving static content.</div>
<div><br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
Ignoring the full "polyglot/poly-server" generality of your question<br>
fo the moment, it seems Nginx specifically could make use of the Shib<br>
SP if $someone contributed code for a "FastCGI authorizer", cf.<br>
<a href="https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPFastCGIConfig" target="_blank">https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPFastCGIConfig</a><br>
Someone with a real interest in Nginx could throw $$$ or manpower at it.<br>
<br></blockquote><div>I agree, I'm not suggesting that any devs take on additional work, and concur whole heartedly that someone interested in Nginx could pony up resources. I'm merely raising the point that there is a viable, third web server that is quite fast, hosts alot of big name sites, that is open source (and thus attractive) that can't use Shibboleth. </div>
<div><br></div><div>I do have control over my environment and can put Apache in front of Java, Python, or Ruby applications, so this is not a personal issue.</div><div><br></div><div> </div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
Or maybe <a href="http://www.lighttpd.net/" target="_blank">http://www.lighttpd.net/</a> is light enough for you -- another<br>
"third, high performance web server".<br></blockquote><div><br></div><div>Not open source and so I've ignored it here.</div><div> </div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<br>
But that's still not what developers want, I'm sure, but no way we're<br>
putting something to productive use based on one of the embedded<br>
(toy?) webservers that come with Python, Ruby, etc.<br></blockquote><div><br></div><div>I'd hesitate to dismiss other languages servers as a toy, though clearly Python and Ruby being interpreted makes them slower. I can remember the same "toy/slow" sentiment with Java and this Apache/IIS problem is a problem for Java as well which I suspect is no longer considered either slow or a toy even by benchmark fanatics. </div>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<br>
Yet another route (as you mention) is to use SimpleSAMLphp for PHP,<br>
pysaml2 for Python, ruby-saml for Ruby, etc., and tie your<br>
applications to those APIs, their upgrade cycles and refactorings<br>
(not to mention severly limited feature sets, in most cases).<br></blockquote><div><br></div><div>So following in the Java SP discussion vein, I guess I'm asking if the library model is the future? While it has been discussed before, technology is a moving target. Is targeting plugins for Web Servers the best strategy? The Devs/Members on the Shibboleth project are two things, developers of specific software, leaders on the vanguard of SAML and federated authentication. How can library based projects tap into the vision without requiring leaders to give up the specific practice (which directly informs the vision)? </div>
<div><br></div><div>Again, I don't have answers, but the project should consider the question from time to time.</div><div> </div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<span class="HOEnZb"><font color="#888888">-peter<br>
</font></span><div class="HOEnZb"><div class="h5">--<br>
To unsubscribe from this list send an email to <a href="mailto:dev-unsubscribe@shibboleth.net">dev-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br><br clear="all"><div><br></div>-- <br>Michael J. McDermott<br>Lead Developer, Identity and Access Management<br>Brown University<br><br><br>