Cantor, Scott cantor.2 at
Mon Nov 24 10:50:01 EST 2014

On 11/24/14, 3:43 PM, "Dave Perry" <Dave.Perry at> wrote:

>If it's DNS, doesn't that take up to 24hours to propagate (worldwide) 
>fully anyway?
>So maybe leave them both on and just sit it out (with a notice to users, 
>if you feel like, saying things might be a bit rocky for a day)?

The TTL is up to the DNS zone, but no, there's no way to fix it. The SPs 
on RH5 will never flush the DNS cache entry, ever, until shibd restarts. 
Red Hat refused to backport the libcurl fix for that bug when I reported 

-- Scott

