Sjibb LDAP pool hangs on firewall TCP session truncation

Daniel Fisher dfisher at vt.edu
Tue Jun 14 10:24:10 EDT 2016


On Mon, Jun 13, 2016 at 4:05 PM, Rich Graves <rgraves at carleton.edu> wrote:

> > Are you setting idp.pool.LDAP.validatePeriod?
>
> Default of 300, which is well below the observed timeout of 1800.
>
> We are small and my IdP has very light load.
>

Edit the ldap-authn-config.xml file and add the following configuration to
the connectionConfig bean:

p:responseTimeout="%{idp.authn.LDAP.responseTimeout:3000}"

You may want a lower timeout than 3 seconds.
I'm still curious why your connections are getting dropped if searches are
occurring every 5 minutes.

--Daniel Fisher
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160614/2331da73/attachment.html>


More information about the users mailing list