<div dir="ltr">We switched over our test boxes with plan do move prod next week for the new InCommon MDQ service.  Java heap size went from 4GB to 1GB or less all the time and the IDP starts up faster.<div><br></div><div>In case you missed this announcement below.</div><div><br></div><div><span class="gmail-description"><p style="margin-top:0pt;margin-bottom:0pt;line-height:1.38" dir="ltr"><span style="color:rgb(0,0,0);font-family:Calibri,Arial,Helvetica,sans-serif;font-size:16px"><span style="font-size:11pt;font-family:Calibri,sans-serif">On January 30th, 2020, the InCommon Federation Technical Advisory Committee </span><a target="_blank" href="http://doi.org/10.26869/TI.142.1"><span style="font-size:11pt;font-family:Calibri,sans-serif">approved the production release</span></a><span style="font-size:11pt;font-family:Calibri,sans-serif"> of
 the new InCommon metadata distribution service, featuring per-entity 
metadata. InCommon strongly recommends you switch your SAML software to 
use the metadata query or “MDQ” features in our new metadata service.</span></span></p><p><span style="color:rgb(0,0,0);font-size:11pt;font-family:Calibri,sans-serif">The
 InCommon “main” metadata aggregate is now almost 70MB in size, and 
requires several gigabytes of memory to parse. This results in enormous 
memory footprints and lengthy start-up times for your SAML software. MDQ
 prevents your software from using these resources by allowing it to 
only fetch the metadata it needs, when it needs it.  You can also read 
about the improvements we made with this service in </span><a target="_blank" href="https://incommon.org/news/organizations-urged-to-move-to-metadata-query-service/" style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:16px"><span style="font-size:11pt;font-family:Calibri,sans-serif">a recent blog post by me</span></a><span style="color:rgb(0,0,0);font-size:11pt;font-family:Calibri,sans-serif">.</span><br></p><p><span style="color:rgb(0,0,0);font-size:11pt;font-family:Calibri,sans-serif">Moving
 to MDQ will  require you to update the configuration of your SAML 
software to point to a new metadata location and to verify the metadata 
using a new public key. The details of all of this are in our new </span><a target="_blank" href="https://spaces.at.internet2.edu/x/2wR0C" style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:16px"><span style="font-size:11pt;font-family:Calibri,sans-serif">metadata distribution service documentation, available in our wiki</span></a><span style="color:rgb(0,0,0);font-size:11pt;font-family:Calibri,sans-serif">.
 Make sure you look at the documentation for Production rather than the 
Technical Preview (the latter is the new version of the old “preview” 
metadata aggregate service).</span><br></p><p><span style="font-family:Calibri,sans-serif;font-size:11pt;color:rgb(0,0,0)">Over
 the next year, we will work with you to transition all InCommon 
federation SAML software to the new service; changing to the new service
 sooner rather than later is recommended.</span><br></p><p><span style="color:rgb(0,0,0);font-family:Calibri,Arial,Helvetica,sans-serif;font-size:16px"> </span></p>  <p style="margin-top:0pt;margin-bottom:0pt;line-height:1.38" dir="ltr"><span style="font-family:Calibri,sans-serif;font-size:11pt;color:rgb(0,0,0)">Best Regards,</span><br></p>  <span style="color:rgb(0,0,0);font-family:Calibri,Arial,Helvetica,sans-serif;font-size:16px"><p style="margin-top:0pt;margin-bottom:0pt;line-height:1.38" dir="ltr"><span style="font-size:11pt;font-family:Calibri,sans-serif">Nick Roy on behalf of InCommon Operations</span></p></span></span></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Fri, Feb 28, 2020 at 10:00 AM Karla Borecky <<a href="mailto:kborecky@smith.edu">kborecky@smith.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="ltr">The InCommon metadata is big - everyone I know (including me) had to increase their Java heap size to accommodate it.</div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Fri, Feb 28, 2020 at 9:47 AM Peter Schober <<a href="mailto:peter.schober@univie.ac.at" target="_blank">peter.schober@univie.ac.at</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">* Ramaiah, Vanna G. <<a href="mailto:ramaiah@musc.edu" target="_blank">ramaiah@musc.edu</a>> [2020-02-28 15:38]:<br>
> After fixing  permission denied error, here is the new error - java<br>
> memory.<br>
<br>
And what's the question about that that a web search wouldn't answer?<br>
<br>
> Also, Should I create an empty InCommon metadada file or the system<br>
> will create one?<br>
<br>
Why would you want an empty file to be created, either manually or by<br>
the software?<br>
So no, you shouldn't have to create that. Of course you do need to<br>
give the user your JVM is running as permissions to write that<br>
metadata to the configured location.<br>
<br>
-peter<br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div><br clear="all"><div><br></div>-- <br><div dir="ltr"><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div style="margin-left:40px"><font face="trebuchet ms, sans-serif">Karla Borecky<br>Systems Administrator, ITS<br></font></div><div style="margin-left:40px"><font face="trebuchet ms, sans-serif">Smith College</font></div><div style="margin-left:40px"><font face="trebuchet ms, sans-serif"><br></font></div><div style="margin-left:40px"><font face="trebuchet ms, sans-serif">Pronouns: she, her, hers</font></div><div style="margin-left:40px"><br></div></div></div></div></div></div></div></div></div></div></div></div>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a></blockquote></div><br clear="all"><div><br></div>-- <br><div dir="ltr" class="gmail_signature"><div dir="ltr"><div><div>Lee Foltz</div><div>Oakland University - UTS</div><div>Senior Identity and Access Management Engineer</div><div> </div><div>248-370-2675</div></div></div></div>