authn eDirectory LDAP and grace logins

Daniel Fisher dfisher at vt.edu
Thu Jul 6 11:56:51 EDT 2017


On Thu, Jul 6, 2017 at 6:56 AM, Glenn Wearen <glenn.wearen at heanet.ie> wrote:

> I removed the password policy control, but the log output is much the
> same. I also added net.shibboleth.idp TRACE logging as the shibb wiki
> suggests but there's no additional logging of the LDAP response. I noticed
> the LDAP provider is org.ldptive.provider.jndi (see log output), should
> this be jldap?
>

No. You can change the provider, but it's not related to your problem.

I also don't get an invalid credentials log message when entering an
> incorrect password on an unexpired account,
>

I don't believe your connection pool is initialized. Do you see errors in
your log at IDP startup?


> 2017-07-06 09:43:06,111 - DEBUG [org.ldaptive.provider.jndi.NamingExceptionUtils:396]
> - could not find result code in naming exception LDAP response read timed
> out, timeout used:3000ms.
>

You've got a stacktrace somewhere that details this error, but your LDAP
isn't responding in less than 3 seconds. Check your LDAP logs to see what's
taking so long.

--Daniel Fisher
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170706/c85afa9c/attachment.html>


More information about the users mailing list