<div dir="ltr">I think that shibd would not be a SPOF  since two nodes running shibd would be in active - passive configuration.<div>From user's point of view failover is seamless (as much as I tested it).</div><div><div>That said, I am not that experienced in Shib world, so any feedback on SP HA is greatly appreciated.</div><div><br><div>But after above discussion, I think I will drop this architecture with shared shibd, and instead have SP in single node, and configure it in active-passive mode. </div><div>What worries me is SSL termination (done at SP machine), as a possible bottleneck if there is a lot of traffic for the Tomcat cluster behind SP.</div><div>But maybe I should start a new thread with SP HA title or something like that.</div><div><br></div><div>-Vedran</div><div><br></div><div> </div></div></div></div><div class="gmail_extra"><br><div class="gmail_quote">On 14 September 2016 at 13:56, Peter Schober <span dir="ltr"><<a href="mailto:peter.schober@univie.ac.at" target="_blank">peter.schober@univie.ac.at</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">* Vedran Bartonicek <<a href="mailto:vbartoni@gmail.com">vbartoni@gmail.com</a>> [2016-09-14 08:47]:<br>
<span class="">> The reason I ended up in this setup is that I am building a HA setup for<br>
> SP, which would lay in front of webserver cluster.<br>
<br>
</span>Are you certain that building a SPOF into the system (one shared shibd<br>
process) qualifies for your HA requirements?<br>
<span class="HOEnZb"><font color="#888888">-peter<br>
</font></span><div class="HOEnZb"><div class="h5">--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br>
</div></div></blockquote></div><br></div>