<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<!--[if !mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]--><style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0cm;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
p.msonormal0, li.msonormal0, div.msonormal0
        {mso-style-name:msonormal;
        mso-margin-top-alt:auto;
        margin-right:0cm;
        mso-margin-bottom-alt:auto;
        margin-left:0cm;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
span.EmailStyle19
        {mso-style-type:personal-reply;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}
@page WordSection1
        {size:612.0pt 792.0pt;
        margin:72.0pt 72.0pt 72.0pt 72.0pt;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-AU" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal"><span style="mso-fareast-language:EN-US">Hi Joseph,<o:p></o:p></span></p>
<p class="MsoNormal"><span style="mso-fareast-language:EN-US">Depending on what the change is either we reload the service(s) or restart tomcat. Its all controlled in the script.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="mso-fareast-language:EN-US">For our prod environment we have an active pair, plus a passive pair of IdP’s with sticky session set on the load balancer.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="mso-fareast-language:EN-US">Updates are done on the passive pair, tested, then they are made active in the load balancer. The old active pair are then taken out of service based on the length of time we have for session time
 out. We then have a fallback in case it went pear shaped for some reason, not all SP’s are available in our devel & qa environment.  If a user needs the new feature they just have to log out of SSO and then restart their SSO session to get redirected to the
 new pair. To the users the update is seamless.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="mso-fareast-language:EN-US"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="mso-fareast-language:EN-US"><o:p> </o:p></span></p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0cm 0cm 0cm">
<p class="MsoNormal" style="margin-left:36.0pt"><b><span lang="EN-US">From:</span></b><span lang="EN-US"> users <users-bounces@shibboleth.net>
<b>On Behalf Of </b>Joseph Fischetti<br>
<b>Sent:</b> Thursday, 6 August 2020 09:24<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Subject:</b> Re: load balancing 2 shibboleth IdP servers<o:p></o:p></span></p>
</div>
</div>
<p class="MsoNormal" style="margin-left:36.0pt"><o:p> </o:p></p>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:0cm;margin-right:0cm;margin-bottom:12.0pt;margin-left:36.0pt">
<span style="font-family:"Arial",sans-serif;color:black">So every time you push a configuration change - you restart?<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:36.0pt"><span style="font-family:"Arial",sans-serif;color:black">Or do you push the configuration files and then restart the necessary services?<o:p></o:p></span></p>
</div>
<div class="MsoNormal" align="center" style="margin-left:36.0pt;text-align:center">
<hr size="2" width="98%" align="center">
</div>
<div id="divRplyFwdMsg">
<p class="MsoNormal" style="margin-left:36.0pt"><b><span style="color:black">From:</span></b><span style="color:black"> users <<a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a>> on behalf of Lipscomb, Gary <<a href="mailto:glipscomb@csu.edu.au">glipscomb@csu.edu.au</a>><br>
<b>Sent:</b> Wednesday, August 5, 2020 7:01:03 PM<br>
<b>To:</b> Shib Users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>><br>
<b>Subject:</b> RE: load balancing 2 shibboleth IdP servers</span> <o:p></o:p></p>
<div>
<p class="MsoNormal" style="margin-left:36.0pt"> <o:p></o:p></p>
</div>
</div>
<div>
<div>
<p class="MsoNormal" style="margin-left:36.0pt">[EXTERNAL EMAIL]<br>
<br>
Same here,<br>
We use puppet to keep all our configurations in sync<br>
Same configuration into devel then qa/uat then production. Full change control process.<br>
<br>
-----Original Message-----<br>
From: users <<a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a>> On Behalf Of Joseph Fischetti<br>
Sent: Thursday, 6 August 2020 03:09<br>
To: Shib Users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>><br>
Subject: Re: load balancing 2 shibboleth IdP servers<br>
<br>
>During upgrades we upgrade the passive site first, evaluate, then make<br>
>it active.  Makes it easy to switch back to the old environment in case<br>
>of any major showstoppers.<br>
<br>
Same<br>
Does anybody have a good mechanism for keeping things in sync?  Things like attribute resolvers/filters and metadata providers?<br>
I find myself testing in test, verifying, and then updating each of our prod servers and reloading their services one by one.  It's cumbersome and error prone.<br>
<br>
--<br>
For Consortium Member technical support, see <a href="http://antispam.csu.edu.au:32224/?dmVyPTEuMDAxJiY3MTg1M2I5ZDMxN2EyYzc2Mz01RjJCM0ZDOV85OTk0MV8xMTg5M18xJiY4ZGE0ODYxODVjM2YwZDQ9MTMzMyYmdXJsPWh0dHBzJTNBJTJGJTJGd2lraSUyRXNoaWJib2xldGglMkVuZXQlMkZjb25mbHVlbmNlJTJGeCUyRmNvRkFBZw==">
https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">
users-unsubscribe@shibboleth.net</a><br>
--<br>
For Consortium Member technical support, see <a href="http://antispam.csu.edu.au:32224/?dmVyPTEuMDAxJiY3MTg1M2I5ZDMxN2EyYzc2Mz01RjJCM0ZDOV85OTk0MV8xMTg5M18xJiY4ZGE0ODYxODVjM2YwZDQ9MTMzMyYmdXJsPWh0dHBzJTNBJTJGJTJGd2lraSUyRXNoaWJib2xldGglMkVuZXQlMkZjb25mbHVlbmNlJTJGeCUyRmNvRkFBZw==">
https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">
users-unsubscribe@shibboleth.net</a><o:p></o:p></p>
</div>
</div>
</div>
</body>
</html>