IdP clustering without Terracotta?
Joel Goguen
joel.goguen at unb.ca
Thu Mar 6 10:36:56 EST 2014
Just to make sure I get this right :) It's the document at https://wiki.shibboleth.net/confluence/display/SHIB2/IdPProxyClustering you're referring to?
If I do that, Shibboleth can still fetch attributes from LDAP/AD and Script attributes still work?
I realized I forgot to mention up front (sorry!) that Shibboleth is the authentication source for our ADFS infrastructure. Does that change your answer any, or make what I want to accomplish more difficult?
--
Joel Goguen
Developer
Enterprise Solutions
Information Technology Services
University of New Brunswick
Email: joel.goguen at unb.ca
Phone: (506) 453-4872
Fax: (506) 453-3590
-----Original Message-----
From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] On Behalf Of Cantor, Scott
Sent: 06 March 2014 10:44
To: Shib Users
Subject: Re: IdP clustering without Terracotta?
On 3/6/14, 9:32 AM, "Joel Goguen" <joel.goguen at unb.ca> wrote:
>- Users must not notice if they get bounced between cluster members -
>it must appear to be a single service from the end-user's perspective.
>
>So... how far out in left field am I? Or is there something that could
>work well for me?
The only way I know of that would address that requirement is what Jim Fox described, using Apache to auto-proxy requests across nodes.
The standard approaches to clustering that don't involve Terracotta and all of the V3 approaches we will support assume stickiness through a transaction.
You may also consider the use of active/passive instead of clustering.
-- Scott
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list