IDPV3: ldap properties in ldap-authn-config.xml

Cantor, Scott cantor.2 at osu.edu
Wed Sep 9 09:59:09 EDT 2015


On 9/9/15, 4:51 AM, "users on behalf of TISSOT Jacques" <users-bounces at shibboleth.net on behalf of jacques.tissot at unifr.ch> wrote:

>
>That was working perfectly with 5 AD servers behind ads.unifr.ch (DNS RoundRobin).

I don't see how that's possible. It can't fail over with a DNS round robin, it only gets one address at a time. If that address is down, it's down. Unless the DNS server itself is detecting failed systems and handing out active ones, but even then you're limited to the TTL of the record to get any fail over.

Of course, it's hanging not because of that but because something is preventing a timeout from actually working, but a timeout/failure is the best case scenario here.

-- Scott



More information about the users mailing list