<div dir="ltr"><div class="gmail_extra"><div class="gmail_quote">On Fri, Apr 14, 2017 at 5:12 PM, Klingenstein, Nate <span dir="ltr"><<a href="mailto:nklingenstein@calstate.edu" target="_blank">nklingenstein@calstate.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">





<div lang="EN-US" link="blue" vlink="purple">
<div class="m_-6086515480406190512WordSection1">
<p class="MsoNormal"><span style="color:rgb(31,73,125);font-family:Calibri,sans-serif;font-size:11pt">I’ll check with the directory administrators about changing the timeout.  We are using a new load balancer endpoint for this.  It’s not a problem, but we had
 to back out the change last time because we didn’t have 3268 uniformly enabled(which I didn’t know about at the time and the escalation never reached me), which eventually exploded with dead connections taking the IdP with it, so management is skittish about
 anything involving WARN and LDAP with null strings.  I appreciate the sanity check.</span></p></div></div></blockquote><div><br></div><div>It's warn because the validator isn't working as it should, but it does reopen the connections.</div><div>Which is why you're not seeing service problems.</div><div>I'm not clear on which 'null' is making you skittish.</div><div>What I see indicates connections are being dropped, whether on the IDP host, the directory host, or something in between you'll have to discover.</div><div><br></div><div>Tuning the validation period down slightly may just do the trick and save you the investigation time.</div><div><br></div><div>--Daniel Fisher</div><div><br></div></div></div></div>