IdP3 Clustering...
Marc SAHIN
marc.sahin at univ-lyon2.fr
Thu Dec 1 06:21:54 EST 2016
> /We have two sites so we need one IdP and one db server(like Mysql) in
> each site in order to ensure BCP. /
//
/That's just not workable. /
I mean to say that each site has one IdP server which access to clustered database like that :
(sorry for the illustration ; I can't send a schema because of message body limitation)
So, both IdP and DB servers behind of F5 with HA.
--
Currently, the configuration of IdP2 running on production is like that :
Load-balancer with Persistence for 60sec,
2 standalone IdP2.3.8 in which has a local mysql db but there is no
replication between them.
Both are actives on production, Is that configuration correct ?
Marc SAHIN
Administrateur Systèmes
Pôle Système - DSI - Université Lumière Lyon 2
04 78 77 26 66
On 30/11/2016 17:23, Cantor, Scott wrote:
> On 11/30/16, 11:07 AM, "users on behalf of Marc SAHIN" <users-bounces at shibboleth.net on behalf of marc.sahin at univ-lyon2.fr> wrote:
>
>> We have two sites so we need one IdP and one db server(like Mysql) in each site in order to ensure BCP.
> That's just not workable.
>
>> Both IdP will be actives on production, if the database replication can be master-slave, a user might have two
>> different Persistent ID...etc until the replication(master will also overwrite dta in slave...) so doesn't it cause
>> data loss or any dysfunction ?
> That would be completely broken from an application point of view.
>
>> Lastly, are the IdP's entities confidential ? I mean that should we put in place a mechanism to protect the data
>> some kind of db replication with ssl ?
> Yes, absolutely.
>
> But that kind of replication is simply not viable for persistent ID management.
>
> -- Scott
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20161201/fc8f5d1c/attachment-0001.html>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: bldknbfpjdfbccid.png
Type: image/png
Size: 3330 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/users/attachments/20161201/fc8f5d1c/attachment-0001.png>
More information about the users
mailing list