Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Warning

After several months of communication with participants, InCommon Operations removed the legacy metadata download endpoint (currently, a redirect) on Wednesday, February 14, 2018

All metadata clients that attempt to download metadata from this endpoint should have switched to one of the production endpoints noted in: Metadata Aggregates before that date. Failure to update to the production metadata locations has likely caused your SAML deployment to break on February 27, 2018 at approximately 2:44 p.m. US Eastern Time.


For many years, InCommon has supported a redirect from a very old metadata download location:

http://wayf.incommonfederation.org/InCommon/InCommon-metadata.xml

And

https://wayf.incommonfederation.org/InCommon/InCommon-metadata.xml

To the current production (“main”) aggregate location:

http://md.incommon.org/InCommon/InCommon-metadata.xml

On February 14, 2018, InCommon Operations REMOVED this redirect.

It is CRITICAL that all production metadata clients be configured to fetch metadata from http://md.incommon.org/InCommon/InCommon-metadata.xml or one of the other three locations on md.incommon.org.

If you currently fetch metadata from one of the old (wayf.incommonfederation.org) locations noted above, you need to reconfigure your deployment. Failure to do so will mean your IdP and/or SPs will break on February 27, 2018.

At the bottom of this page, you will find a list of hosts, updated weekly, that are still downloading metadata from the old location. If you see a host on the list that is at your organization, please contact the relevant systems personnel to arrange to switch metadata consumption to one of the supported aggregates.

Please pass along this information to anyone in your organization who is responsible for running an IdP or SP in InCommon, especially those such as delegated administrators or other systems administrators who may not be subscribed to this mailing list.


Note

The information below was last updated on ThursdayMonday, March 0105, 2018

IMPORTANT: The table on the left is a list of root DNS zones with hosts still attempting to access the legacy metadata location. The table on the right is a list of actual hosts still attempting to access the legacy metadata.


REMINDER: When you make a configuration change to target one of the current production metadata aggregate locations, you may need to restart your SAML SP software (shibd/etc) to cause it to re-read the configuration.


Hosts still downloading from legacy metadata endpoint
1137.211.93.208.in-addr.arpa
2141.154.251.23.bc.googleusercontent.com
3193.211.93.208.in-addr.arpa4216-139-212-28.aus.us.siteprotect.com
542252-00f1-bc01.ucsfmedicalcenter.org
652252-00f1-bc02.ucsfmedicalcenter.org
762408-0c50-bc01.ucsfmedicalcenter.org
872408-0c50-bc02.ucsfmedicalcenter.org
843.61.184.35.bc.googleusercontent.com
95-10-31-155.everestdc.com
105-10-31-164.everestdc.com
115-10-31-182.everestdc.com
125-10-31-214.everestdc.com
1364-129-18-90.static.twtelecom.net1469-168-255-13.brainerd.net
151469-168-255-40.brainerd.net
161569-168-255-43.brainerd.net
171669-168-255-62.brainerd.net
1869-196-252-6.blackboard.com
1917ACMWEB06.acm.org
2018ACMWEB10.acm.org
2119al2s-demo.net.internet2.edu
2220aragusa-dev6.grnoc.iu.edu
2321atg-pool.nat.uw.edu
2422cloudvpn1.code42.com
2523cloudvpn2.code42.com
2624cluster1.serialssolutions.com
2725collections.library.illinois.edu
2826cp.nursing.jhu.edu
2927crowd-surf.surf.nl
3028crowd-test.surfnet.nl
3129crowd.surfnet.nl
3230ctl.jhsph.edu
3331dhn-c5-efs.duhs.duke.edu
3432docdelivery2.trondent.com
3533dora.uark.edu
3634dpoc.uark.edu
37dtst.uark.edu
38e.safetysmart.com
3539ec2-107-22-198-108.compute-1.amazonaws.com
4036ec2-107-22-238-17.compute-1.amazonaws.com
4137ec2-107-23-147-38.compute-1.amazonaws.com
4238ec2-107-23-200-82.compute-1.amazonaws.com
4339ec2-107-23-78-15.compute-1.amazonaws.com
4440ec2-13-56-255-37.us-west-1.compute.amazonaws.com45ec2-184-72-147-129.compute-1.amazonaws.com
4641ec2-34-194-230-61.compute-1.amazonaws.com
4742ec2-34-226-222-114.compute-1.amazonaws.com
4843ec2-50-17-229-101.compute-1.amazonaws.com
4944ec2-52-1-179-223.compute-1.amazonaws.com
5045ec2-52-10-19-174.us-west-2.compute.amazonaws.com
5146ec2-52-20020-73215-158192.compute-1.amazonaws.com
5247ec2-52-206-216-95.compute-1.amazonaws.com
5348ec2-52-21-240-124.compute-1.amazonaws.com
54ec2-52-44-72-12.compute-1.amazonaws.com
5549ec2-52-6-126-78.compute-1.amazonaws.com
56ec2-52-6-171-239.compute-1.amazonaws.com
5057ec2-52-7-144-22.compute-1.amazonaws.com
5851ec2-52-87-255-118.compute-1.amazonaws.com59ec2-52-91-134-224.compute-1.amazonaws.com
6052ec2-54-146-225-47.compute-1.amazonaws.com
6153ec2-54-147-125-241.compute-1.amazonaws.com
6254ec2-54-164-203-179.compute-1.amazonaws.com
6355ec2-54-175-119-5.compute-1.amazonaws.com
6456ec2-54-175-50-103.compute-1.amazonaws.com
6557ec2-54-186-107-10.us-west-2.compute.amazonaws.com
6658ec2-54-210-41-28.compute-1.amazonaws.com
6759ec2-54-210-58-241.compute-1.amazonaws.com
6860ec2-54-211-88-6.compute-1.amazonaws.com
6961ec2-54-221-238-160.compute-1.amazonaws.com
70ec2-54-236-123-217.compute-1.amazonaws.com
6271ec2-54-81-80-221.compute-1.amazonaws.com
7263ec2-54-85-240-29.compute-1.amazonaws.com
7364ec2-54-87-226-206.compute-1.amazonaws.com
7465ec2-54-88-67-127.compute-1.amazonaws.com
7566esappi11.uits.iu.edu
7667esappi12.uits.iu.edu
7768eth0-0-fw3-1-ap-q18-va2.blackboard.com
7869eth0-0-fw3-1-ap-q18-va2.mhint
7970eth0-0-fw3-1-ap-r137-3-va3.blackboard.com
8071eth0-0-fw3-1-ap-r137-3-va3.mhint
8172ewebproxy.thomsonreuters.com
8273fischer-gig.fischerinternational.com
8374fischerwall.fisc.com
8475fw-msp--sw-core-msp--4009.code42.com
8576gannicus.las.uic.edu
8677ginger.autonomy.ri.cmu.edu
8778gis.accc.uic.edu
8879git.bmi.osumc.edu
8980gmoc-db.grnoc.iu.edu
9081google2.utsystem.edu
9182gradleaders-vsrx.expedient.com
92gw1-va2.blackboard.com
93h82.74.130.40.static.ip.windstream.net
94host-128-227-104-209.xlate.ufl.edu
95host-128-227-251-1.xlate.ufl.edu
8396hq.atomiclearning.com
97iamt-fp-02.it.ohio-state.edu
8498ip-128-239-61-105.v4.wm.edu
99ip-42-36-244-173.west.us.northamericancoax.com
100ip-61-36-244-173.west.us.northamericancoax.com
101ip68-228-243-4.ph.ph.cox.net
85iquise.mit.edu
86102ITDEV2.QATAR.CMU.EDU
103library.proxy.mbl.edu
87104mblfw.whoi.net
105nanohub.org
88106net253.is.jhsph.edu
10789net4.jhsph.edu
10890node2150.it.mtu.edu
10991ocw.jhsph.edu
11092ohcininetng-fw01.cengage.com
11193OIR-Data.server.uic.edu
11294pc4.sdn-test.grnoc.iu.edu
11395prod-01.ebi.berkeley.edu
11496proxy-ext1.osumc.edu
115raweb101.refworks.com
116raweb102.refworks.com
117raweb103.refworks.com
118raweb104.refworks.com
119raweb105.refworks.com
120raweb106.refworks.com
121raweb107.refworks.com
97122raweb108.refworks.com
12398sc.vizientinc.com
12499sdg-dev.cites.illinois.edu
125100shba.it.ucla.edu
126101shib-d1.calnet.berkeley.edu
127102shib-test2.gatech.edu
128shibb-discovery.mbl.edu
103129srfseward1.rfsuny.org
130104sso.sdstate.edu
131star.eblib.com
105132t2pguardian01.t2hosted.com
133temp-staging.asc.ohio-state.edu
134106topiawww1.webair.com
135107trln-dev.trln.org
136108trlnr610a.trln.org
137109tshib02.ucmerced.edu
110unknown-host.kennisnet.org
111138vm-bs-158-38-213-170.cl.uninett.no
139112vpn.cloudtricity.com
140113vx26.ucsf.edu
141web06.srv.cs.cmu.edu
142webauth.school.da.org
114143webmail.atg.travel
144115webmail.imleagues.com
145116webproxy1.anl.gov
146117webproxy2.anl.gov