IDP Login Delay Question

Joseph Lucia jlucia at cysd.k12.pa.us
Thu Mar 27 15:08:02 EDT 2014


I have IDP and LDAP logs set for trace, there are no additional details for that delay outside what I have copied, I was hoping it would shed some light. I tried using those parameters from that previous thread with no luck, but I am also not using aliases and I think that was their issue, plus I am only 5 seconds compared to their 60 seconds. My wireshark is logging all traffic from the IDP server to the DC. The DC is the top domain.

Thanks,

Joseph Lucia
Information Systems Specialist
Central York School District
717-846-6789 x1211
jlucia at cysd.k12.pa.us

From: Douglas E Engert <deengert at gmail.com<mailto:deengert at gmail.com>>
Reply-To: Shib Users <users at shibboleth.net<mailto:users at shibboleth.net>>
Date: March 27, 2014 Mar 27, 2014 ~ 2:55 PM
To: "users at shibboleth.net<mailto:users at shibboleth.net>" <users at shibboleth.net<mailto:users at shibboleth.net>>
Subject: Re: IDP Login Delay Question


On 3/27/2014 1:25 PM, Joseph Lucia wrote:

I built a new IDP from scratch, CentOS6.5/Apache Tomcat/Shib IDP 2.4.0 and
I get stuck for 5 seconds in the same spot. What is interesting is the
first time you log in after a reboot there is no delay. If you log out,
close the browser and wait about 2 minutes, then log in again, it has the
login delay.

Have your tried getting a TRACE log rather then DEBUG log?

The message tread:  Re: Extremely slow IdP login<http://marc.info/?t=134389983500001&r=1&w=2>

http://shibboleth.net/pipermail/users/2012-August/005180.html

has a number of other suggestions.


http://shibboleth.net/pipermail/users/2012-August/005193.html

Has a solution.


Is your AD domain part of a forest? Is it the top domain?

In your Wireshark trace, were you tracing everything, or just LDAP?




13:58:27.103 - DEBUG
[edu.vt.middleware.ldap.handler.DefaultConnectionHandler:128] - Set
hostname verifier for ldaps
13:58:32.118 - DEBUG [edu.vt.middleware.ldap.ssl.AggregateTrustManager:75]
- invoking checkServerTrusted for
sun.security.ssl.X509TrustManagerImpl at 3dbb2cc9

I added the global catalog port and changed the DN login to be
username at domain.com<mailto:username at domain.com> and still no luck. I don't have a different Active
Directory to connect to for testing although if it was getting stuck
connecting to the did, I should see that in the packet capture which I am
not.


Joseph Lucia
Information Systems Specialist
Central York School District
717-846-6789 x1211
jlucia at cysd.k12.pa.us<mailto:jlucia at cysd.k12.pa.us>






On Mar 27, 2014 ~ Mar 27, 2014 ~ 9:39 AM 9:39 AM, "Peter Schober"
<peter.schober at univie.ac.at><mailto:peter.schober at univie.ac.at> wrote:



* Peter Schober <peter.schober at univie.ac.at><mailto:peter.schober at univie.ac.at> [2014-03-27 14:38]:


Servers being called dc (domain controller) is this MS-Active
Directory? Isn't there some issue with subtree searches from the
baseDN (and whether or not to connect to the Global Catalog port or
not)?


Lots of stuff to check/try there:
https://wiki.shibboleth.net/confluence/display/SHIB2/LdapServerIssues
-peter
--
To unsubscribe from this list send an email to
users-unsubscribe at shibboleth.net<mailto:users-unsubscribe at shibboleth.net>

--
CONFIDENTIALITY NOTICE – This email message, including any attachments, is for the sole use of the intended recipient(s) and may contain confidential and privileged information. Any unauthorized review, use, disclosure, or distribution is prohibited. If you are not the intended recipient, please contact the sender by reply email and destroy all copies of the original message.
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net<mailto:users-unsubscribe at shibboleth.net>


--

 Douglas E. Engert  <DEEngert at gmail.com><mailto:DEEngert at gmail.com>



--
CONFIDENTIALITY NOTICE – This email message, including any attachments, is for the sole use of the intended recipient(s) and may contain confidential and privileged information. Any unauthorized review, use, disclosure, or distribution is prohibited. If you are not the intended recipient, please contact the sender by reply email and destroy all copies of the original message.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20140327/6fd9ea34/attachment-0001.html 


More information about the users mailing list