Shibboleth Daemon Service (32-bit) crashing

Manoj Kancharla manojk at silverchair.com
Wed Oct 21 15:50:38 EDT 2015


Scott,

We're loading the metadata for the UK and German federations (http://metadata.ukfederation.org.uk/ukfederation-metadata.xml and http://www.aai.dfn.de/fileadmin/metadata/DFN-AAI-Basic-metadata.xml).
We have multiple clients using UK and German federations. It appears it is doing the remote resource check for every client-federation combination.   In our Shibboleth2.xml file, we have an <ApplicationOverride> for each site, that contains <MetadataProvider> nodes.

How could we add the metadata filtering (to strip out all the SPs from the metadata)? Could you provide some detailed information or point us to some documentation?

Let me know if you need any further information to help us diagnose the problem. 

Thanks

-----Original Message-----
From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Cantor, Scott
Sent: Wednesday, October 21, 2015 2:32 PM
To: Shib Users
Subject: Re: Shibboleth Daemon Service (32-bit) crashing 

On 10/21/15, 2:13 PM, "users on behalf of Manoj Kancharla" <users-bounces at shibboleth.net on behalf of manojk at silverchair.com> wrote:



>We are a service provider and currently provide shibboleth services to about 6-7 of our clients. Our web applications run under 32-bit (because of OpenAthens SP limitations) – when the shibboleth(32) process starts/initializes, the memory consumed by shibd.exe reaches the 2gb limit and sometimes crashes. As a result, we are unable to add more clients to use shibboleth.
> 
>Has anyone run into this? Are there any workarounds? Could there be a memory leak?

There aren't any significant leaks.

What metadata sources are you loading? I can't do it any time soon, but my sandbox is still 32-bit so I can reproduce that set and see how much it takes to load them all.

You could also make sure you have appropriate metadata filtering added, such as stripping out all the SPs from the metadata. It really depends where the expansion is happening.

-- Scott

-- 
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list