From masarati@aero.polimi.it Thu Dec 6 18:25:56 2012 From: masarati@aero.polimi.it To: openldap-bugs@openldap.org Subject: Re: (ITS#7464) ldap_back_dobind_int breaking binded user Date: Thu, 06 Dec 2012 18:25:55 +0000 Message-ID: <201212061825.qB6IPttJ035841@boole.openldap.org> MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="===============8785826870222624670==" --===============8785826870222624670== Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 7bit > --20cf307811d0d379c404d032d6ee > Content-Type: text/plain; charset=ISO-8859-1 > > Config is basic (with special timeout tests commented out) : > > database ldap > suffix "o=corp" > uri ldaps://10.100.120.153 > > # close connection after a timeout > #idletimeout 100 > # causes a cached connection to be dropped an recreated after a given ttl > #conn-ttl 4294967294 > # close connection after a timeout for ldap backend > #idle-timeout 4294967294 > # Discards current cached connection when the client rebinds - default to > No > #single-conn no Try adding a "rebind-as-user" here. This forces back-ldap to store client's credentials in order to rebind when needed (e.g. because a persistent connection timed out). p. > overlay rwm > rwm-suffixmassage "o=corp" "o=int" > > > 2012/12/6 Pierangelo Masarati > >> >> > Full_Name: Sebastien Prune THOMAS >> > Version: slapd 2.4.31 >> > OS: Linux CentOS >> > URL: ftp://ftp.openldap.org/incoming/ >> > Submission from: (NULL) (206.167.157.64) >> > >> > >> > I use OpenLdap to proxy (with the module back-ldap) to a eDirectory >> LDAP >> > server. >> > Every once and a while I have long lasting connections re-binding as >> > anonymous, >> > breaking the actual bind. >> > This usualy happen after hitting either the idle-timeout or the >> conn-ttl >> > limit. >> > I wasn't able to find out what these values are when not set... but >> > setting them >> > low can help reproduce the problem : >> >> What is the configuration of back-ldap? Can you post it (after >> sanitizing >> sensitive info)? >> >> p. >> >> -- >> Pierangelo Masarati >> Associate Professor >> Dipartimento di Ingegneria Aerospaziale >> Politecnico di Milano >> >> > > --20cf307811d0d379c404d032d6ee > Content-Type: text/html; charset=ISO-8859-1 > Content-Transfer-Encoding: quoted-printable > >
Config is basic (with > spec= > ial timeout tests commented out) :
style=3D"font-family:Tahoma;fo= > nt-size:13px">=A0
style=3D"font-family:Tahoma;font-size:13px">dat= > abase =A0 =A0 =A0ldap
> suffix =A0 =A0 =A0 =A0 =A0 > =A0"o=3Dcorp"
uri=A0=A0=A0=A0=A0=A0= > =A0=A0=A0=A0=A0=A0=A0 =A0 =A0ldaps://10.100.120.153
style= > =3D"font-family:Tahoma;font-size:13px">=A0
style=3D"font-family:T= > ahoma;font-size:13px"># close connection after a timeout
> #idletimeout=A0=A0=A0=A0 100
# causes a cached connection to be dropped > = > an recreated after a given ttl
#conn-ttl=A0=A0=A0=A0=A0=A0=A0 > 4294967294= >
# close connection after a timeout for ldap > backend
#idle-timeout=A0= > =A0=A0 4294967294
# Discards current cached connection when the client > r= > ebinds - default to No
> #single-conn=A0=A0=A0=A0 no
style=3D"font-family:Tahoma;font-size= > :13px">
overlay=A0=A0=A0=A0=A0=A0=A0=A0 rwm
rwm-suffixmassage > "o= > =3Dcorp" "o=3Dint"
class=3D"gmail_extra">

<= > div class=3D"gmail_quote">2012/12/6 Pierangelo Masarati dir=3D"ltr">&= > lt; target=3D"_blank">masarati(a)ae= > ro.polimi.it>
>
.8ex;border-left:1p= > x #ccc solid;padding-left:1ex">
> > Full_Name: Sebastien Prune THOMAS
> > Version: slapd 2.4.31
> > OS: Linux CentOS
> > URL: target=3D"_blank">ft= > p://ftp.openldap.org/incoming/
> > Submission from: (NULL) (206.167.157.64)
> >
> >
> > I use OpenLdap to proxy (with the module back-ldap) to a eDirectory > LD= > AP
> > server.
> > Every once and a while I have long lasting connections re-binding > as r> > > anonymous,
> > breaking the actual bind.
> > This usualy happen after hitting either the idle-timeout or the > conn-t= > tl
> > limit.
> > I wasn't able to find out what these values are when not set... > bu= > t
> > setting them
> > low can help reproduce the problem :
>
> What is the configuration of back-ldap? =A0Can you post it (after > sanitizin= > g
> sensitive info)?
>
> p.
>
> --
> Pierangelo Masarati
> Associate Professor
> Dipartimento di Ingegneria Aerospaziale
> Politecnico di Milano
>
>

> > --20cf307811d0d379c404d032d6ee-- > > > > > -- Pierangelo Masarati Associate Professor Dipartimento di Ingegneria Aerospaziale Politecnico di Milano --===============8785826870222624670==--