<html><head><base href="x-msg://76/"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; ">The Terracotta project has regularly been breaking APIs and failing to provide backward compatibility in configuration to earlier versions, and doing this in between major releases. &nbsp;At each new minor release version, there have been differences to accommodate, so use of a newer version is not recommended unless you have the time to sort out and test those differences.<div><br></div><div>Because of this and issues with high load, Terracotta is not necessarily the ideal choice.</div><div><br></div><div><div><div>I use TC version 3.5.1 in production for Shibboleth, both on Linux and Solaris, and this has been very stable.</div><div><br></div><div>This is an option if you don't have hundreds of thousands of logins every day, or you have plenty of hardware.</div><div><br></div><div>Another recommended solution is to use the cryptographic plugin for generating and responding to NameIDs.</div><div><a href="https://wiki.shibboleth.net/confluence/display/SHIB2/ResolverCryptoTransientIDAttributeDefinition">https://wiki.shibboleth.net/confluence/display/SHIB2/ResolverCryptoTransientIDAttributeDefinition</a></div><div><a href="https://wiki.shibboleth.net/confluence/display/SHIB2/CryptoTransientPrincipalConnector">https://wiki.shibboleth.net/confluence/display/SHIB2/CryptoTransientPrincipalConnector</a></div><div><br></div><div>This allows for attribute queries between nodes without clustering.</div><div><br></div><div>For this to be a complete solution, you would either need perfect session stickiness with a loadbalancer, or use the Ohio State plugin for using previous session information from a cookie: &nbsp;This is available on the contributions page:</div><div><a href="https://wiki.shibboleth.net/confluence/display/SHIB2/Contributions">https://wiki.shibboleth.net/confluence/display/SHIB2/Contributions</a></div><div><br></div><div>There is also another clustering solution based on Infinispan available from that page.</div><div><br></div><div>Regards,</div><div>Russ.</div><div><br></div><div>On Oct 11, 2012, at 12:45 AM, Baird-Parker, David wrote:</div><br class="Apple-interchange-newline"><blockquote type="cite"><div lang="EN-GB" link="blue" vlink="purple"><div class="WordSection1" style="page: WordSection1; "><div style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif; ">Hi everyone,<o:p></o:p></div><div style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif; ">now that we have an IdP back up and running we ideally want to have a second machine.&nbsp; Naively, I thought it would just be a case of adding a second server and load balancing which works to a point but logins fail on server 2.&nbsp; I’ve been advised by the UK Fed to follow the instructions at<span class="Apple-converted-space">&nbsp;</span><a href="https://wiki.shibboleth.net/confluence/display/SHIB2/IdPCluster" style="color: blue; text-decoration: underline; ">https://wiki.shibboleth.net/confluence/display/SHIB2/IdPCluster</a><o:p></o:p></div><div style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif; "><o:p>&nbsp;</o:p></div><div style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt; font-size: 10.5pt; font-family: Consolas; "><span style="font-size: 11pt; font-family: Calibri, sans-serif; ">However,</span><span class="Apple-converted-space">&nbsp;</span><span style="font-size: 11pt; font-family: Calibri, sans-serif; ">those instructions are for Terracotta 3.2.1 and the current version is 3.7.0 available from<span class="Apple-converted-space">&nbsp;</span><a href="http://terracotta.org/downloads/open-source/catalog" style="color: blue; text-decoration: underline; ">http://terracotta.org/downloads/open-source/catalog</a><o:p></o:p></span></div><div style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif; ">and as I’ve got Windows servers what would have been available as an exe file now only seems to be available as a jar file so I’m thinking a lot could go wrong if I try to apply the previous instructions to the new version.<o:p></o:p></div><div style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif; "><o:p>&nbsp;</o:p></div><div style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif; ">Has anyone got experience with this version of Terracotta?&nbsp; If so, what did you do differently to previous versions and how well does it work. &nbsp;If you’ve used something else to make multiple IdP’s work together that you think might serve us better I’d like to know about that too before starting on this.<o:p></o:p></div><div style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif; "><o:p>&nbsp;</o:p></div><div style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif; ">Any help would be appreciated.<o:p></o:p></div><div style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif; "><o:p>&nbsp;</o:p></div><div style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif; ">Thanks,<o:p></o:p></div><div style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif; ">David<o:p></o:p></div></div><pre>--

To see our email disclaimer click here <a href="http://www.norfolk.gov.uk/emaildisclaimer" style="color: blue; text-decoration: underline; ">http://www.norfolk.gov.uk/emaildisclaimer</a>
</pre>--<br>To unsubscribe from this list send an email to<span class="Apple-converted-space">&nbsp;</span><a href="mailto:users-unsubscribe@shibboleth.net" style="color: blue; text-decoration: underline; ">users-unsubscribe@shibboleth.net</a></div></blockquote></div><br></div></body></html>