Project

General

Profile

Task #3578

Task #3394: Deploy Shibboleth provider for KNB LDAP accounts

Determine which host will run IdP software

Added by Ben Leinfelder almost 12 years ago. Updated over 11 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Ben Leinfelder
Category:
-
Target version:
Start date:
2013-02-15
Due date:
% Done:

100%

Milestone:
None
Product Version:
*
Story Points:
Sprint:

Description

We are looking to deploy two instances of the Shibboleth IdP software, both pointing to different subtrees in ldap.ecoinformatics.org.

Where should they be deployed? We definitely need Tomcat and Apache and a secure connection to the ldap server.

History

#1 Updated by Matthew Jones almost 12 years ago

The current LDAP service is running on triana.nceas.ucsb.edu, and it makes sense that the shibboleth services would run on the same machine. This needs to be discussed with Nick Brand, but I think it will be the best location.

#2 Updated by Ben Leinfelder almost 12 years ago

I'm in the process of deploying two IdPs on one machine to see if they can coexist. So far so good, but I still need to get this newer IdP registered with CILogon to make sure.

#3 Updated by Ben Leinfelder almost 12 years ago

I have the ou=Account and the o=unaffiliated accounts both running on the same mn-demo-5.test.dataone.org server in the CILogon test environment. So I think we should be good running two (or more) IdPs on the same server in the same Tomcat container. We do have to do a couple more configuration steps to use contexts other than "idp" but they are pretty trivial.

So, is triana the one?

#4 Updated by Ben Leinfelder almost 12 years ago

Talked to Nick about the set-up:

Will make new VM on the same host that houses triana.nceas.ucsb.edu.

Deploy each IdP using distinct hostnames:

identity.nceas.ucsb.edu (ou=Account)

identity.ecoinformatics.org (o=unaffiliated)

This means we need another IP for the VM

#5 Updated by Nick Outin almost 12 years ago

The new server is up. Ben has sudo, hostname is frey.nceas.ucsb.edu.

I set it up with monitoring, nightly tape backups, and stats collection.

#6 Updated by Ben Leinfelder almost 12 years ago

  • translation missing: en.field_remaining_hours set to 0.0
  • Status changed from New to Closed

Host is up; there are other tickets for deploying the individual instances.

#7 Updated by Ben Leinfelder over 11 years ago

  • Target version changed from 2013.2-Block.1.1 to 2013.10-Block.2.1

#8 Updated by Ben Leinfelder over 11 years ago

  • Target version set to 2013.10-Block.2.1

#9 Updated by Ben Leinfelder over 11 years ago

  • Target version deleted (2013.10-Block.2.1)

Also available in: Atom PDF

Add picture from clipboard (Maximum size: 14.8 MB)