<div dir="ltr"><div class="gmail_extra"><div class="gmail_quote">On Thu, Apr 21, 2016 at 12:16 PM, Youssef  GHORBAL <span dir="ltr"><<a href="mailto:youssef.ghorbal@pasteur.fr" target="_blank">youssef.ghorbal@pasteur.fr</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">        On the shibboleth side, I was wondering if there is any reasons not setting a default p:responseTimeout on the LDAP connection pools. Maybe there are other non obvious side effects ?<br></blockquote><div><br></div><div>I can't think of any bad side effects. Being an authentication subsystem I think an aggressive timeout is reasonable, something around 3 seconds. Of course, you'll probably be better off fixing the cause of the TCP hangs, but I know that's not always possible. Note that tuning the pool validation settings may also have some value here.</div><div><br></div><div>--Daniel Fisher</div><div><br></div></div></div></div>