<html>
  <head>
    <meta content="text/html; charset=windows-1252"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <blockquote type="cite">
      <pre wrap=""><i>   We have two sites so we need one IdP and one db server(like Mysql) in each site in order to ensure BCP.
</i></pre>
    </blockquote>
    <i>
    </i>
    <pre wrap=""><i>That's just not workable.
</i>
I mean to say that each site has one IdP server which access to clustered database like that :
(sorry for the illustration ; I can't send a schema because of message body limitation)
</pre>
    <img src="cid:part1.31912D6C.4714C533@univ-lyon2.fr" alt=""><br>
    <br>
    So, both IdP and DB servers behind of F5 with HA.<br>
    --<br>
    Currently, the configuration of IdP2 running on production is like
    that :<br>
    Load-balancer with Persistence for 60sec,<br>
    2 standalone IdP2.3.8 in which has a local mysql db but there is no
    replication between them.<br>
    Both are actives on production, Is that configuration correct ?<br>
    <br>
    <pre class="moz-signature" cols="72">Marc SAHIN
Administrateur Systèmes
Pôle Système  - DSI - Université Lumière Lyon 2
04 78 77 26 66
</pre>
    <div class="moz-cite-prefix">On 30/11/2016 17:23, Cantor, Scott
      wrote:<br>
    </div>
    <blockquote cite="mid:F28B2B16-5ACB-4141-B733-54C87A4DB4DD@osu.edu"
      type="cite">
      <pre wrap="">On 11/30/16, 11:07 AM, "users on behalf of Marc SAHIN" <a class="moz-txt-link-rfc2396E" href="mailto:users-bounces@shibboleth.netonbehalfofmarc.sahin@univ-lyon2.fr"><users-bounces@shibboleth.net on behalf of marc.sahin@univ-lyon2.fr></a> wrote:

</pre>
      <blockquote type="cite">
        <pre wrap="">   We have two sites so we need one IdP and one db server(like Mysql) in each site in order to ensure BCP.
</pre>
      </blockquote>
      <pre wrap="">
That's just not workable.

</pre>
      <blockquote type="cite">
        <pre wrap="">   Both IdP will be actives on production, if the database replication can be master-slave, a user might have two
different Persistent ID...etc until the replication(master will also overwrite dta in slave...) so doesn't it cause
data loss or any dysfunction ?
</pre>
      </blockquote>
      <pre wrap="">
That would be completely broken from an application point of view.

</pre>
      <blockquote type="cite">
        <pre wrap="">   Lastly, are the IdP's entities confidential ? I mean that should we put in place a mechanism to protect the data
some kind of db replication with ssl ?
</pre>
      </blockquote>
      <pre wrap="">
Yes, absolutely.

But that kind of replication is simply not viable for persistent ID management.

-- Scott


</pre>
    </blockquote>
    <br>
  </body>
</html>