--- Begin Message ---
Title: Proxy authorization required
This is related to the nsslapd-idlistscanlimit attribute. See the text below (extracted from Redhat Doc):
In Directory Server, when examining
an index, if more than a certain number of entries are found, the
server stops reading the index and marks the search as unindexed for
that particular index.
The threshold number of entries is called the idlistscanlimit
and is configured with the nsslapd-idlistscanlimit
configuration attribute. The default value is 4000
which is designed to give good performance for a common range of
database sizes and access patterns. Typically, it is not necessary to
change this value. However, in rare circumstances it may be possible to
improve search performance with a different value. For example,
lowering the value will improve performance for searches that will
otherwise eventually hit the default limit of 4000. This might reduce
performance for other searches that benefit from indexing. Conversely,
increasing the limit could improve performance for searches that were
previously hitting the limit. With a higher limit, these searches could
benefit from indexing where previously they did not.
More information:
Em 03/07/2009 às 10:52 horas, fedora-directory-users@xxxxxxxxxx escreveu:
I have a search problem with Fedora DS 1.1.3.
My directory has an extended schema on the objectClass "inetOrgPerson".
It contains 350000 inetOrgPerson objects.
When I proceed a search with that kind of filter (cn=smith*) or
(uid=25698*) the response comes 1 minute later with a error code 11.
Indexes on cn and uid attribute are on equality, presence and
substring. I have recreated (plus reindexed) this attribute.
I put the look-through-limit to infinity though I don't have the errror
code 11 anymore but I have to wait a very long time the response.
In the log, I found "etime=77 notes=U" which means that the search does
not use the indexes.
I have done the same requests with a "native" schema : it works
perfectly. So, it is my extended schema which causes the problem.
Can the Fedora DS (or 389 DS) deal with extended schema ?
Does anybody met this problem ? Is there a solution for forcing FDS to
use the indexes ?
Thanks you
Ce message est protégé par les règles relatives au secret des correspondances. Il est donc établi à destination exclusive de son destinataire. Celui-ci peut donc contenir des informations confidentielles. La divulgation de ces informations est à ce titre rigoureusement interdite. Si vous avez reçu ce message par erreur, merci de le renvoyer à l'expéditeur dont l'adresse e-mail figure ci-dessus et de détruire le message ainsi que toute pièce jointe.
This message is protected by the secrecy of correspondence rules. Therefore, this message is intended solely for the attention of the addressee. This message may contain privileged or confidential information, as such the disclosure of these informations is strictly forbidden. If, by mistake, you have received this message, please return this message to the addressser whose e-mail address is written above and destroy this message and all files attached.
Proxy authorization required
Username authentication is required for using this proxy.
Either your browser does not perform proxy authorization, or your
authorization has failed.
--- End Message ---
"Esta mensagem do SERVIÇO FEDERAL DE PROCESSAMENTO DE DADOS (SERPRO), empresa pública federal regida pelo disposto na Lei Federal nº 5.615, é enviada exclusivamente a seu destinatário e pode conter informações confidenciais, protegidas por sigilo profissional. Sua utilização desautorizada é ilegal e sujeita o infrator às penas da lei. Se você a recebeu indevidamente, queira, por gentileza, reenviá-la ao emitente, esclarecendo o equívoco."
"This message from SERVIÇO FEDERAL DE PROCESSAMENTO DE DADOS (SERPRO) -- a government company established under Brazilian law (5.615/70) -- is directed exclusively to its addressee and may contain confidential data, protected under professional secrecy rules. Its unauthorized use is illegal and may subject the transgressor to the law's penalties. If you're not the addressee, please send it back, elucidating the failure."
389 users mailing list