Debug PTA and PAM-PTA stack for ldap timeout

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hello,

We are having some ldap timeout issues in out MMR-SLAVE ldap setup. A
user is unable to ssh to random hosts at random times.

Terminal Error: Permission denied (publickey,gssapi-with-mic,password)
secure logs:  pam_ldap: ldap_result Timed out
              Failed password for psundaram from 10.1.0.120 port 22039
ssh2


Sifting thru logs tell the user's password was successfully
authenticated upstream by looking at dirsrv access log with err=0. The
clients connecting to slave incur regular timeouts and the login fails
but it is not case with clients connecting to Master directly.

Setup: Two Masters with MMR, Two Slaves with MMR. The authentication for
clients connecting to the slave ldap server goes to the master via PTA
plugin and then from Master it goes to Windows AD via PAM-PTA.

Client----->Slave--(PTA)-->Master--(PAM-PTA)-->AD(This is where all
passwords are)

I understand we have might have a long traversal for the authentication,
but we have set considerably high timeout limits.

/etc/ldap.conf
timelimit 120
bind_timelimit 5 
bind_policy hard
idle_timelimit 3600

slave ldap server
nsslapd-idletimeout: 86400
nsbindtimeout: 15
nsslapd-timelimit: 3600

Master ldap server
nsslapd-idletimeout: 7200
nsbindtimeout: 15
nsslapd-timelimit: 3600


Anybody had similar issue or can share some debugging tips?

-Prashanth



[Index of Archives]     [Fedora User Discussion]     [Older Fedora Users]     [Fedora Announce]     [Fedora Package Announce]     [EPEL Announce]     [Fedora News]     [Fedora Cloud]     [Fedora Advisory Board]     [Fedora Education]     [Fedora Security]     [Fedora Scitech]     [Fedora Robotics]     [Fedora Maintainers]     [Fedora Infrastructure]     [Fedora Websites]     [Anaconda Devel]     [Fedora Devel Java]     [Fedora Legacy]     [Fedora Desktop]     [Fedora Fonts]     [ATA RAID]     [Fedora Marketing]     [Fedora Management Tools]     [Fedora Mentors]     [Fedora Package Review]     [Fedora R Devel]     [Fedora PHP Devel]     [Kickstart]     [Fedora Music]     [Fedora Packaging]     [Centos]     [Fedora SELinux]     [Fedora Legal]     [Fedora Kernel]     [Fedora QA]     [Fedora Triage]     [Fedora OCaml]     [Coolkey]     [Virtualization Tools]     [ET Management Tools]     [Yum Users]     [Tux]     [Yosemite News]     [Yosemite Photos]     [Linux Apps]     [Maemo Users]     [Gnome Users]     [KDE Users]     [Fedora Tools]     [Fedora Art]     [Fedora Docs]     [Maemo Users]     [Asterisk PBX]     [Fedora Sparc]     [Fedora Universal Network Connector]     [Fedora ARM]

  Powered by Linux