<div dir="ltr"><div dir="ltr">On Tue, Apr 9, 2019 at 3:03 PM cneberg <<a href="mailto:cneberg@gmail.com">cneberg@gmail.com</a>> wrote:<br></div><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">What is the expected behavior of the ldap data connector on the lasted<br>
IDP when the ldap server returns 3 LDAP_TIMELIMIT_EXCEEDED?</blockquote><div><br></div><div>The IDP will process whatever results it has received, that's typically none since most searches are looking for a single entry.</div><div> </div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
One of my upstream ldap servers is over burdened and it appears some<br>
users who should be found in ldap are not.   Then it seems to continue<br>
their sso session with no attributes.<br></blockquote><div><br></div><div>If you're seeing timeLimitExceeded then you're likely processing an empty result set. Check your logs to confirm.</div><div><br></div><div>--Daniel Fisher</div><div> </div></div></div>