Shibboleth SP getting progressively slower

Cantor, Scott cantor.2 at
Thu Jan 19 16:21:48 GMT 2012

On 1/19/12 10:22 AM, "Steve Thorpe" <thorpe at> wrote:
>It seems likely we also encountered this bottleneck at MCNC, though it
>wasn't with load testing per se.  In our case we had an end-to-end (SP
>-> WAYF -> IdP -> SP) Nagios monitoring check running once per minute,
>24x7. Gradually over a period of a few weeks, the SP took longer and
>longer to service each login request.  At a certain point, they were
>taking >20 seconds each, and the Nagios monitor started timing out and
>complaining.  We modified the configuration so the NameID was no longer
>sent from the IdP to the SP, and the problem went away.

I can see that being the case, except that when load testing isn't
involved, the old records are supposed to purge and I thought that applied
to the NameID->session reverse index also. If I'm wrong about that, that
might explain it, I'll try and check.

-- Scott

