IDP 3 LDAPConnector
Hong Ye
hy93 at cornell.edu
Thu Mar 3 10:25:22 EST 2016
Hello,
I have two questions regarding LDAP connector.
1. Our IDP 3 use active_passive connectionStrategy and default value of searchTimeLimit which is 5 seconds. To test the fail over, we shut down the directory service of the first AD on the list, it seem it took more than a minute to finish aacli.sh command. Before the shutdown, it took less than 3 seconds to complete aacli.sh command. After directory service shutdown, it took about 62 seconds to finish the same command. Is there any configuration change I can make so that the failover happen faster?
2.When ROUND_ROBIN connectionStrategy is used, if ldap server being used for the new connection is down, will IDP try the next ldap url on the list?
Thanks,
Hong
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160303/660c7204/attachment-0001.html>
More information about the users
mailing list