LDAP timeout errors

Lee, Dong DLee at umaryland.edu
Tue Feb 4 16:43:46 UTC 2025


Hello, we are running shib version 4.2.1 and had the following error last week.    The understanding is exactly what the error message says, the connection to xxxxx-lb timed out after 3000 ms.     We are trying to determine was this shibboleth causing the problem, was this the load balancer, networking in general, something else?     How would we determine where the issue was?

The second part of the question: if the search timed out, why did the assertion go across?  It appears that with the double pipe, no attributes were sent?     Should this be a fatal error?

2025-01-28 12:07:32,096 - ERROR [net.shibboleth.idp.profile.impl.ResolveAttributes:317] - 10.226.70.238 - Profile Action ResolveAttributes: Error resolving attributes
net.shibboleth.idp.attribute.resolver.ResolutionException: Data Connector 'umbLDAP': Unable to execute LDAP search
        at net.shibboleth.idp.attribute.resolver.dc.ldap.impl.LDAPDataConnector.retrieveAttributes(LDAPDataConnector.java:225)
Caused by: org.ldaptive.LdapException: LDAPException(resultCode=85 (timeout), numEntries=0, numReferences=0, diagnosticMessage='A client-side timeout was encountered while waiting 3000ms for a response to search request with message ID 140, base DN 'ou=xxxx,dc=xxxx,dc=xxxx,dc=xxxx', scope SUB, and filter '(uid=xxxxx)' from server xxxxx-lb.umaryland.edu:636.', ldapSDKVersion=4.0.14, revision=c0fb784eebf9d36a67c736d0428fb3577f2e25bb')
        at org.ldaptive.provider.ProviderUtils.throwOperationException(ProviderUtils.java:55)
Caused by: com.unboundid.ldap.sdk.LDAPSearchException: A client-side timeout was encountered while waiting 3000ms for a response to search request with message ID 140, base DN 'ou=xxxx,dc=xxxx,dc=xxxx,dc=xxx', scope SUB, and filter '(uid=xxxx' from server xxxxx-lb.umaryland.edu:636.
        at com.unboundid.ldap.sdk.SearchRequest.process(SearchRequest.java:1206)

2025-01-28 12:07:32,104 - INFO [Shibboleth-Audit.SSO:283] - 10.226.70.238 - 10.226.70.238|2025-01-28T17:07:32.104614Z|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect|_950e5c979f28f73ec8be11f2f371332b|cfapps1.umaryland.edu/sp|http://shibboleth.net/ns/profiles/saml2/sso/browser|https://webauth.umaryland.edu/idp/shibboleth|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST|_f83d6656df4ec4106b5cf2f0a51f7350|xxxxx|urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport||AAdzZWNyZXQx35m8zFPoeJJWUWJ1UMtFx3Gl6aLHuMVIWPa2V7XYWQSToThPHXqAwIJvjHJ8XOHjWGridsnLiIRi6bSOIf0Xhf23HVjOhbTd7FtqYPV46IWQ75l4WHw6/GKjFDtm|_db71f7d9698b8b52d5ac46cc06ac6887|


Also is this related to search timeout?
2025-01-28 12:05:24,604 - WARN [org.ldaptive.pool.BlockingConnectionPool:784] -  - org.ldaptive.pool.AbstractConnectionPool$DefaultPooledConnectionProxy at 119e70d<mailto:org.ldaptive.pool.AbstractConnectionPool$DefaultPooledConnectionProxy at 119e70d> failed validation
2025-01-28 12:05:24,853 - INFO [org.ldaptive.pool.BlockingConnectionPool:497] -  - added available connection: org.ldaptive.pool.AbstractConnectionPool$DefaultPooledConnectionProxy at 42b6aaa1<mailto:org.ldaptive.pool.AbstractConnectionPool$DefaultPooledConnectionProxy at 42b6aaa1>


Dong Lee

Identity Management & System Integration
Center for Information Technology Services
University of Maryland, Baltimore
410-706-3027
dlee at umaryland.edu<mailto:dlee at umaryland.edu>


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20250204/5af5f2ca/attachment.htm>


More information about the users mailing list