<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Verdana;
        panose-1:2 11 6 4 3 5 4 4 2 4;}
@font-face
        {font-family:\2019Calibri\2019;
        panose-1:0 0 0 0 0 0 0 0 0 0;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
span.EmailStyle19
        {mso-style-type:personal-reply;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="blue" vlink="purple" style="word-wrap:break-word">
<div class="WordSection1">
<p class="MsoNormal">We’re still on v4.1.6, so I should upgrade and try again.  I should have mentioned initially that setting idp.authn.LDAP.connectionStrategy explicitly by uncommenting it doesn’t work either.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<div>
<p class="MsoNormal">Steven Teixeira<o:p></o:p></p>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b>From:</b> users <users-bounces@shibboleth.net> <b>On Behalf Of
</b>Daniel Fisher via users<br>
<b>Sent:</b> Tuesday, June 21, 2022 6:02 AM<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Cc:</b> Daniel Fisher <dfisher@vt.edu><br>
<b>Subject:</b> Re: Multiple ldapURL values in ldap.properties<o:p></o:p></p>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<div style="border:solid #9C6500 4.5pt;padding:2.0pt 2.0pt 2.0pt 2.0pt">
<p class="MsoNormal" style="line-height:16.0pt;background:#FFEB9C"><u><span style="font-size:14.0pt;font-family:"’Calibri’",serif;color:#900528">CAUTION:
</span></u><span style="font-size:14.0pt;font-family:"’Calibri’",serif;color:black">This message originated from outside of Stanislaus State. Do not click on links or open attachments unless you recognize the sender and are expecting the message.<o:p></o:p></span></p>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<div>
<div>
<div>
<div>
<p class="MsoNormal"><span style="font-family:"Arial",sans-serif">On Mon, Jun 20, 2022 at 2:55 PM Steven Teixeira <<a href="mailto:steixeira@csustan.edu">steixeira@csustan.edu</a>> wrote:</span><span style="font-family:"Verdana",sans-serif"><o:p></o:p></span></p>
</div>
</div>
<div>
<blockquote style="border:none;border-left:solid #CCCCCC 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in">
<div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto">We recently changed our idp.authn.LDAP.ldapURL value from a single DNS round robin entry to multiple servers, separated by space.  As below:<br>
idp.authn.LDAP.ldapURL = ldaps://<a href="https://nam04.safelinks.protection.outlook.com/?url=http%3A%2F%2Fserver1.example.org%2F&data=05%7C01%7Csteixeira%40csustan.edu%7C4ce16131215a4335a40a08da53865155%7Cbee5690713df4af2a4bfd7ef0debc01c%7C0%7C0%7C637914133619330704%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=rltQ4A4pPyiRm%2BfR4w3EU42GJlcKy9HVrprYxWJwxQ0%3D&reserved=0" target="_blank">server1.example.org</a>
 ldaps://<a href="https://nam04.safelinks.protection.outlook.com/?url=http%3A%2F%2Fserver2.example.org%2F&data=05%7C01%7Csteixeira%40csustan.edu%7C4ce16131215a4335a40a08da53865155%7Cbee5690713df4af2a4bfd7ef0debc01c%7C0%7C0%7C637914133619330704%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=vriRp3yG%2Fxkahgm7lWmWwrgxjk3YbqKM0oWJ2rWzIY4%3D&reserved=0" target="_blank">server2.example.org</a>
 ldaps://<a href="https://nam04.safelinks.protection.outlook.com/?url=http%3A%2F%2Fserver3.example.org%2F&data=05%7C01%7Csteixeira%40csustan.edu%7C4ce16131215a4335a40a08da53865155%7Cbee5690713df4af2a4bfd7ef0debc01c%7C0%7C0%7C637914133619330704%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=J%2B%2BbHubPCmJnAQEpyJ3dbpNZLoTLTX0NoxhUtdMRPCc%3D&reserved=0" target="_blank">server3.example.org</a>
 ldaps://<a href="https://nam04.safelinks.protection.outlook.com/?url=http%3A%2F%2Fserver4.example.org%2F&data=05%7C01%7Csteixeira%40csustan.edu%7C4ce16131215a4335a40a08da53865155%7Cbee5690713df4af2a4bfd7ef0debc01c%7C0%7C0%7C637914133619330704%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=xzRV0TGxJbQ3hAAajgDHgbOeK%2Byr9%2Bps6J7v6heNE94%3D&reserved=0" target="_blank">server4.example.org</a><o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"> <o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto">idp.attribute.resolver.LDAP.ldapURL is set as below:<br>
idp.attribute.resolver.LDAP.ldapURL = %{idp.authn.LDAP.ldapURL}<br>
<br>
During testing of this change, the failover behavior was as expected.  Authentication was immediate when server1 was up.  After powering down server1, authentication took 3 seconds longer(the timeout value).  After powering down server2, with server 1 still
 powered off, authentication took 6 seconds longer(3 seconds per server).  This continued through server 4.  So we believed this to be working.  However, last week, it became clear that authentication was happening primarily on server4, the last entry in the
 space delimited list.  Further, when server4 was unreachable, the IdP didn’t even try to authenticate against any of the other LDAP servers listed.<o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"> <o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto">The lines for idp.authn.LDAP.connectionStrategy and idp.attribute.resolver.LDAP.connectionStrategy are as follows:<br>
#idp.authn.LDAP.connectionStrategy = ACTIVE_PASSIVE<o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto">idp.attribute.resolver.LDAP.connectionStrategy = %{idp.authn.LDAP.connectionStrategy:ACTIVE_PASSIVE}<o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"> <o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto">So, our impression is that ACTIVE_PASSIVE is the current setting since it should be the default value.  Has anyone else run into behavior like this, or did I just miss something
 obvious?<o:p></o:p></p>
</div>
</div>
</blockquote>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Verdana",sans-serif">What version of the IDP are you running? There was a bug that caused that behavior if no connectionStrategy was configured. Explicitly setting `idp.authn.LDAP.connectionStrategy` or running
 the latest version of the IDP should fix this issue.<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Verdana",sans-serif"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Verdana",sans-serif">--Daniel Fisher<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-family:"Verdana",sans-serif"><o:p> </o:p></span></p>
</div>
</div>
</div>
</div>
</div>
</body>
</html>