<div dir="ltr"><div>I could see the SP requesting /profile/SAML2/SOAP/ArtifactResolution on the IdP port 8443 on the new IP. So the DNS change was already propagated. <br><br></div>On the SP, I saw just this:<br><br>2014-11-24 13:18:36 ERROR Shibboleth.ArtifactResolver [6920]: exception resolving SAML 2.0 artifact: Incorrect content type (text/html;charset=iso8859-7) for SOAP response.<br><br><br></div><div class="gmail_extra"><br><div class="gmail_quote">On Mon, Nov 24, 2014 at 5:50 PM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">On 11/24/14, 3:43 PM, "Dave Perry" <<a href="mailto:Dave.Perry@hull-college.ac.uk">Dave.Perry@hull-college.ac.uk</a>> wrote:<br>
<br>
>If it's DNS, doesn't that take up to 24hours to propagate (worldwide)<br>
>fully anyway?<br>
>So maybe leave them both on and just sit it out (with a notice to users,<br>
>if you feel like, saying things might be a bit rocky for a day)?<br>
<br>
</span>The TTL is up to the DNS zone, but no, there's no way to fix it. The SPs<br>
on RH5 will never flush the DNS cache entry, ever, until shibd restarts.<br>
Red Hat refused to backport the libcurl fix for that bug when I reported<br>
it.<br>
<div class="HOEnZb"><div class="h5"><br>
-- Scott<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br><br clear="all"><br>-- <br><div class="gmail_signature">Athanasios Douitsis<br><br><br></div>
</div>