IDP HA -- Why?

Rod Widdowson rdw at steadingsoftware.com
Sun Mar 9 05:36:15 EDT 2014


Most obviously, they will loose the single sign on if the user heads off to another SP and will have to sign in again.

Sent from my iPad

> On 9 Mar 2014, at 08:57, Sam Agnew <saa2012 at qatar-med.cornell.edu> wrote:
> 
> Simple (possibly stupid) question here.
> 
> If I have a user who has authenticated and now have a valid session my understanding is that they are good with the SP until cookie expires. 
> 
> If my IDP fails over to another IDP that doesn't know anything about the sessions my user is still good. Where is the benefit in fiddling with Teracotta/memcached to get session retention during failover?
> 
> Thanks!
> 
> Sam
> 
> 
> 
> --
> Sam Agnew
> System Administrator
> IT Department
> Weill Cornell Medical College in Qatar
> 
> 
> 
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20140309/0fa31b5b/attachment.html 


More information about the users mailing list