On Tue, Aug 2, 2011 at 5:33 AM, Manuel Haim <span dir="ltr">&lt;<a href="mailto:haim@hrz.uni-marburg.de">haim@hrz.uni-marburg.de</a>&gt;</span> wrote:<br><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex;">
Daniel,<br>
<div class="im"><br>
&gt;<br>
&gt; Early versions of the 2.x IDP attempted to use connection pooling for<br>
&gt; DN resolution, with mixed results due to some bugs. Ultimately we<br>
&gt; decided it simply violated the stateless nature of JAAS and moved to<br>
&gt; the current implementation which opens and closes a connection for<br>
&gt; every DN lookup. Open a feature request for this, it&#39;s a good time for<br>
&gt; me to review this again.<br>
&gt;<br>
&gt;<br>
<br>
</div>thanks for your comment, I&#39;ve just added an issue under<br>
<a href="http://code.google.com/p/vt-middleware/issues/detail?id=118" target="_blank">http://code.google.com/p/vt-middleware/issues/detail?id=118</a><br><br></blockquote><div><br></div><div>Thanks. This comment in the issue is disconcerting:</div>
<div><br></div><meta charset="utf-8"><blockquote class="gmail_quote" style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0.8ex; border-left-width: 1px; border-left-color: rgb(204, 204, 204); border-left-style: solid; padding-left: 1ex; ">
<span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px; ">It is indeed the LDAP bind operations reducing performance, each taking about 50ms and somehow blocking the whole Shibboleth IdP.</span> </blockquote>
<div><br></div><div>Do you have any logs demonstrating that the IDP is blocking on DN resolution specifically or JAAS authentication generally?</div><div><br></div><div>--Daniel Fisher</div><div><br></div></div>