IdP clustering without Terracotta?

Joel Goguen joel.goguen at unb.ca
Thu Mar 6 10:36:56 EST 2014


Just to make sure I get this right :) It's the document at https://wiki.shibboleth.net/confluence/display/SHIB2/IdPProxyClustering you're referring to?

If I do that, Shibboleth can still fetch attributes from LDAP/AD and Script attributes still work? 

I realized I forgot to mention up front (sorry!) that Shibboleth is the authentication source for our ADFS infrastructure. Does that change your answer any, or make what I want to accomplish more difficult?

-- 
Joel Goguen
Developer
Enterprise Solutions
Information Technology Services
University of New Brunswick
Email: joel.goguen at unb.ca
Phone: (506) 453-4872
Fax: (506) 453-3590


-----Original Message-----
From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] On Behalf Of Cantor, Scott
Sent: 06 March 2014 10:44
To: Shib Users
Subject: Re: IdP clustering without Terracotta?

On 3/6/14, 9:32 AM, "Joel Goguen" <joel.goguen at unb.ca> wrote:
>- Users must not notice if they get bounced between cluster members - 
>it must appear to be a single service from the end-user's perspective.
>
>So... how far out in left field am I? Or is there something that could 
>work well for me?

The only way I know of that would address that requirement is what Jim Fox described, using Apache to auto-proxy requests across nodes.

The standard approaches to clustering that don't involve Terracotta and all of the V3 approaches we will support assume stickiness through a transaction.

You may also consider the use of active/passive instead of clustering.

-- Scott


--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list