Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Note
titleDeprecated

Note that this page has been deprecated; the information it contains is no longer current. It has been retained for historical purposes only.

Warning

After several months of communication with participants, InCommon Operations removed the legacy metadata download endpoint (currently, a redirect) on Wednesday, February 14, 2018

All metadata clients that attempt to download metadata from this endpoint should have switched to one of the production endpoints noted in: Metadata Aggregates before that date. Failure to update to the production metadata locations has likely caused your SAML deployment to break on February 27, 2018 at approximately 2:44 p.m. US Eastern Time.


For many years, InCommon has supported a redirect from a very old metadata download location:

http://wayf.incommonfederation.org/InCommon/InCommon-metadata.xml

And

https://wayf.incommonfederation.org/InCommon/InCommon-metadata.xml

To the current production (“main”) aggregate location:

http://md.incommon.org/InCommon/InCommon-metadata.xml

On February 14, 2018, InCommon Operations REMOVED this redirect.

It is CRITICAL that all production metadata clients be configured to fetch metadata from http://md.incommon.org/InCommon/InCommon-metadata.xml or one of the other three locations on md.incommon.org.

If you currently fetch metadata from one of the old (wayf.incommonfederation.org) locations noted above, you need to reconfigure your deployment. Failure to do so will mean means that your IdP and/or SPs will break broke on February 27, 2018.

At the bottom of this page, you will find a list of hosts, updated weekly, that are still downloading metadata from the old location. If you see a host on the list that is at your organization, please contact the relevant systems personnel to arrange to switch metadata consumption to one of the supported aggregates.

Please pass along this information to anyone in your organization who is responsible for running an IdP or SP in InCommon, especially those such as delegated administrators or other systems administrators who may not be subscribed to this mailing list.


Note

The information below was last updated on MondayThursday, March 0529, 2018.

IMPORTANT: The table on the left is a list of root DNS zones with hosts still attempting to access the legacy metadata location. The table on the right is a list of actual hosts still attempting to access the legacy metadata.


REMINDER: When you make a configuration change to target one of the current production metadata aggregate locations, you may need to restart your SAML SP software (shibd/etc) to cause it to re-read the configuration.


Hosts still downloading from attempting to use legacy metadata endpoint
1137.211.93.208.in-addr.arpa
2141.154.251.23.bc.googleusercontent.com
3204.11.hqserv.co.il
4204.13.hqserv.co.il
5204.7.hqserv.co.il
6216-139-212-28.aus.us.siteprotect.com
472252-00f1-bc01.ucsfmedicalcenter.org
582252-00f1-bc02.ucsfmedicalcenter.org
692408-0c50-bc01.ucsfmedicalcenter.org
7102408-0c50-bc02.ucsfmedicalcenter.org
843.61.184.35.bc.googleusercontent.com
1195-10-31-155.everestdc.com
10125-10-31-164.everestdc.com
11135-10-31-182.everestdc.com
12145-10-31-214.everestdc.com
131569-168-255-13.brainerd.net
1469-168-255-40.brainerd.net
151669-168-255-43.brainerd.net
161769-168-255-62.brainerd.net
1718ACMWEB06.acm.org
1819ACMWEB10.acm.org
1920al2s-demo.net.internet2.edu
2021aragusa-dev6.grnoc.iu.edu
2122atg-pool.nat.uw.edu
2223cloudvpn1borked.code42wpi.comedu
2324cloudvpn2.code42.com
2425cluster1.serialssolutions.com
2526collections.library.illinois.edu
27comphxuawifi.telcom.arizona.edu
2826cp.nursing.jhu.edu
2729crowd-surf.surf.nl
2830crowd-test.surfnet.nl
2931crowd.surfnet.nl
3032ctl.jhsph.edu
3133dhn-c5-efs.duhs.duke.edu
3234docdelivery2.trondent.com
3335dora.uark.edu
3436dpoc.uark.edu
3537ec2-107-22-198-108.compute-1.amazonaws.com
3638ec2-107-22-238-17.compute-1.amazonaws.com
3739ec2-107-23-147-38.compute-1.amazonaws.com
3840ec2-107-23-200-82.compute-1.amazonaws.com
3941ec2-107-23-78-15.compute-1.amazonaws.com
4042ec2-184-72-147-129.compute-1.amazonaws.com
4143ec2-34-194226-230222-61114.compute-1.amazonaws.com
4244ec2-34-226-222-114.compute-1241-142-178.eu-west-1.compute.amazonaws.com
45ec2-34-242-188-254.eu-west-1.compute..amazonaws.com
4346ec2-34-244-5022-17231.eu-229west-1011.compute.amazonaws.com
47ec2-34-245-216-146.eu-west-1.compute.amazonaws.com
4448ec2-34-250-27-55.eu-west-1.compute.amazonaws.com
49ec2-50-17-229-101-52-1-179-223.compute-1.amazonaws.com
4550ec2-52-101-19179-174223.us-west-2.computecompute-1.amazonaws.com
4651ec2-52-20-215-192.compute-1.amazonaws.com
4752ec2-52-206-216-95.compute-1.amazonaws.com
4853ec2-52-21-240-124.compute-1.amazonaws.com
54ec2-52-214-28-159.eu-west-1.compute.amazonaws.com
5549ec2-52-6-126-78.compute-1.amazonaws.com
5056ec2-52-7-144-22.compute-1.amazonaws.com
5157ec2-52-91-134-224.compute-1.amazonaws.com
5258ec2-54-146-225-47.compute-1.amazonaws.com
5359ec2-54-147-125-241.compute-1.amazonaws.com
5460ec2-54-164-203-179.compute-1.amazonaws.com
5561ec2-54-175-119-5.compute-1.amazonaws.com56ec2-54-175-50-103.compute-1.amazonaws.com
5762ec2-54-186-107-10.us-west-2.compute.amazonaws.com
5863ec2-54-210-41-28.compute-1.amazonaws.com
5964ec2-54-210-58-241.compute-1.amazonaws.com
6065ec2-54-211-88-6.compute-1.amazonaws.com
6166ec2-54-221-238-160.compute-1.amazonaws.com
6267ec2-54-81229-80205-221205.computeeu-west-1.compute.amazonaws.com
6368ec2-54-85-240-29.compute-1.amazonaws.com
6469ec2-54-87-226-206.compute-1.amazonaws.com
6570ec2-54-88-67-127.compute-1.amazonaws.com
6671esappi11.uits.iu.edu
6772esappi12.uits.iu.edu
6873eth0-0-fw3-1-ap-q18-va2.blackboard.com
6974eth0-0-fw3-1-ap-q18-va2.mhint
7075eth0-0-fw3-1-ap-r137-3-va3.blackboard.com
7176eth0-0-fw3-1-ap-r137-3-va3.mhint
7277ewebproxy.thomsonreuters.com
7378fischer-gig.fischerinternational.com
7479fischerwall.fisc.com
7580fw-msp--sw-core-msp--4009.code42.com
7681gannicus.las.uic.edu
7782ginger.autonomy.ri.cmu.edu
7883gis.accc.uic.edu
7984git.bmi.osumc.edu
8085gmoc-db.grnoc.iu.edu
8186google2.utsystem.edu
8287gradleaders-vsrx.expedient.com
8388hq.atomiclearning.com
89idp.mbl.edu
9084ip-128-239-61-105.v4.wm.edu
85iquise.mit.edu
91ip-20-36-244-173.west.us.northamericancoax.com
9286ITDEV2.QATAR.CMU.EDU
93library.proxy.mbl.edu
94mail.ts24.com
9587mblfw.whoi.net
8896net253.is.jhsph.edu
8997net4.jhsph.edu
9098node2150.it.mtu.edu
9199ocw.jhsph.edu
92100ohcininetng-fw01.cengage.com
93OIR-Data.server.uic.edu
10194pc4.sdn-test.grnoc.iu.edu
95prod-01.ebi.berkeley.edu
10296proxy-ext1ext3.osumc.edu
97103raweb108.refworks.com
98104sc.vizientinc.com
99105sdg-dev.cites.illinois.edu
100shba.it.ucla.edu
101106shib-d1.calnet.berkeley.edu
102107shib-test2.gatech.edu
103108srfseward1shibb-discovery.rfsunymbl.orgedu
104109ssosrfseward1.sdstaterfsuny.eduorg
105110t2pguardian01.t2hosted.com
106111topiawww1.webair.com
107112trln-dev.trln.org
108113trlnr610a.trln.org
109114tshib02.ucmerced.edu
110unknown-host.kennisnet.org
115111vm-bs-158-38-213-170.cl.uninett.no
112116vpn.cloudtricity.com
113117vx26.ucsf.edu
114webmail.atg.travel
115118webmail.imleagues.com
116webproxy1.anl.gov
117webproxy2.anl.gov