Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Warning

After several months of communication with participants, InCommon Operations removed the legacy metadata download endpoint (currently, a redirect) on Wednesday, February 14, 2018

All metadata clients that attempt to download metadata from this endpoint should have switched to one of the production endpoints noted in: Metadata Aggregates before that date. Failure to update to the production metadata locations has likely caused your SAML deployment to break on February 27, 2018 at approximately 2:44 p.m. US Eastern Time.


For many years, InCommon has supported a redirect from a very old metadata download location:

http://wayf.incommonfederation.org/InCommon/InCommon-metadata.xml

And

https://wayf.incommonfederation.org/InCommon/InCommon-metadata.xml

To the current production (“main”) aggregate location:

http://md.incommon.org/InCommon/InCommon-metadata.xml

On February 14, 2018, InCommon Operations REMOVED this redirect.

It is CRITICAL that all production metadata clients be configured to fetch metadata from http://md.incommon.org/InCommon/InCommon-metadata.xml or one of the other three locations on md.incommon.org.

If you currently fetch metadata from one of the old (wayf.incommonfederation.org) locations noted above, you need to reconfigure your deployment. Failure to do so means that your IdP and/or SPs broke on February 27, 2018.

At the bottom of this page, you will find a list of hosts, updated weekly, that are still downloading metadata from the old location. If you see a host on the list that is at your organization, please contact the relevant systems personnel to arrange to switch metadata consumption to one of the supported aggregates.

Please pass along this information to anyone in your organization who is responsible for running an IdP or SP in InCommon, especially those such as delegated administrators or other systems administrators who may not be subscribed to this mailing list.


Note

The information below was last updated on Friday, March 16, 2018.

IMPORTANT: The table on the left is a list of root DNS zones with hosts still attempting to access the legacy metadata location. The table on the right is a list of actual hosts still attempting to access the legacy metadata.


REMINDER: When you make a configuration change to target one of the current production metadata aggregate locations, you may need to restart your SAML SP software (shibd/etc) to cause it to re-read the configuration.


Hosts still attempting to use legacy metadata endpoint
1137.211.93.208.in-addr.arpa
2141.154.251.23.bc.googleusercontent.com
3216-139-212-28.aus.us.siteprotect.com
42252-00f1-bc01.ucsfmedicalcenter.org
52252-00f1-bc02.ucsfmedicalcenter.org
62408-0c50-bc01.ucsfmedicalcenter.org
72408-0c50-bc02.ucsfmedicalcenter.org
85-10-31-155.everestdc.com
95-10-31-164.everestdc.com
105-10-31-182.everestdc.com
115-10-31-214.everestdc.com
1250-205-70-183-static.hfc.comcastbusiness.net1369-168-255-13.brainerd.net
141369-168-255-43.brainerd.net
151469-168-255-62.brainerd.net
161569-196-252-6.blackboard.com
1716ACMWEB06.acm.org
1817ACMWEB10.acm.org
1918al2s-demo.net.internet2.edu
2019aragusa-dev6.grnoc.iu.edu
2120atg-pool.nat.uw.edu
2221borked.wpi.edu
23cloudvpn1.code42.com
2422cloudvpn2.code42.com
2523cluster1.serialssolutions.com
2624collections.library.illinois.edu
27comphxuawifi.telcom.arizona.edu
2825cp.nursing.jhu.edu
2926crowd-surf.surf.nl
3027crowd-test.surfnet.nl
3128crowd.surfnet.nl
3229ctl.jhsph.edu
3330dhn-c5-efs.duhs.duke.edu
3431docdelivery2.trondent.com
3532dora.uark.edu
3633dpoc.uark.edu
3734ec2-107-22-198-108.compute-1.amazonaws.com
3835ec2-107-22-238-17.compute-1.amazonaws.com
3936ec2-107-23-147-38.compute-1.amazonaws.com
4037ec2-107-23-200-82.compute-1.amazonaws.com
4138ec2-107-23-78-15.compute-1.amazonaws.com
4239ec2-184-72-147-129.compute-1.amazonaws.com
4340ec2-34-226-222-114.compute-1.amazonaws.com
4441ec2-50-17-229-101.compute-1.amazonaws.com
4542ec2-52-1-179-223.compute-1.amazonaws.com
46ec2-52-10-19-174.us-west-2.compute.amazonaws.com
4743ec2-52-20-215-192.compute-1.amazonaws.com
4844ec2-52-206-216-95.compute-1.amazonaws.com
4945ec2-52-21-240-124.compute-1.amazonaws.com
5046ec2-52-6-126-78.compute-1.amazonaws.com
5147ec2-52-7-144-22.compute-1.amazonaws.com
5248ec2-52-91-134-224.compute-1.amazonaws.com
5349ec2-54-146-225-47.compute-1.amazonaws.com
5450ec2-54-147-125-241.compute-1.amazonaws.com
5551ec2-54-164-203-179.compute-1.amazonaws.com
5652ec2-54-166-254-34.compute-1.amazonaws.com57ec2-54-175-50-103.compute-1.amazonaws.com
5853ec2-54-186-107-10.us-west-2.compute.amazonaws.com
5954ec2-54-210-41-28.compute-1.amazonaws.com
6055ec2-54-210-58-241.compute-1.amazonaws.com
6156ec2-54-211-88-6.compute-1.amazonaws.com
6257ec2-54-221-238-160.compute-1.amazonaws.com
6358ec2-54-85-240-29.compute-1.amazonaws.com
6459ec2-54-87-226-206.compute-1.amazonaws.com
6560ec2-54-88-67-127.compute-1.amazonaws.com
6661esappi11.uits.iu.edu
6762esappi12.uits.iu.edu
68eth0-0-fw3-1-ap-q18-va2.blackboard.com
6963eth0-0-fw3-1-ap-q18-va2.mhint
7064eth0-0-fw3-1-ap-r137-3-va3.blackboard.com
7165eth0-0-fw3-1-ap-r137-3-va3.mhint
7266ewebproxy.thomsonreuters.com
7367fischer-gig.fischerinternational.com
7468fischerwall.fisc.com
7569fw-msp--sw-core-msp--4009.code42.com
7670gannicus.las.uic.edu
7771ginger.autonomy.ri.cmu.edu
7872gis.accc.uic.edu
7973git.bmi.osumc.edu
8074gmoc-db.grnoc.iu.edu
8175google2.utsystem.edu
8276gradleaders-vsrx.expedient.com
77gw1-va2.blackboard.com
78host169.dyn153.wfu.edu
7983hq.atomiclearning.com
8480idp.mbl.edu
81intimeclick.com
8285ip-128-239-61-105.v4.wm.edu
83ip-30-36-244-173.west.us.northamericancoax.com
84ip-84-36-244-173.west.us.northamericancoax.com
8586ITDEV2.QATAR.CMU.EDU
8786library.proxy.mbl.edu
8887mblfw.whoi.net
8988net253.is.jhsph.edu
9089net4.jhsph.edu
9190node2150.it.mtu.edu
92oars3.ehs.washington.edu
9391ocw.jhsph.edu
9492ohcininetng-fw01.cengage.com
9593pc4.sdn-test.grnoc.iu.edu
9694proxy-ext3.osumc.edu
9795raweb108.refworks.com
9896sc.vizientinc.com
9997sdg-dev.cites.illinois.edu
10098shib-d1.calnet.berkeley.edu
10199shib-test2.gatech.edu
102100srfseward1.rfsuny.org
101startraining.ssw.washington.edu
102103t2pguardian01.t2hosted.com
104103topiawww1.webair.com
105104trln-dev.trln.org
106105trlnr610a.trln.org
107106tshib02.ucmerced.edu
108107vm-bs-158-38-213-170.cl.uninett.no
109108vpn.cloudtricity.com
110109vx26.ucsf.edu
111110webmail.atg.travel
112111webmail.imleagues.com
113webproxy1.anl.gov
114webproxy2.anl.gov