I'm attaching the debug log files here. I also found this:
2017-07-10 13:03:14,955 WARN [org.apereo.cas.authentication.LdapAuthenticationHandler] - <The principal id attribute [uid] is not found. CAS cannot construct the final authenticated principal if it's unable to locate the attribute that is designated as the principal id. Attributes available on the LDAP entry are [[]]. Since principal id attribute is not available, CAS will fallback to construct the principal based on the provided user id: cfernand> 2017-07-10 13:03:14,955 DEBUG [org.apereo.cas.authentication.LdapAuthenticationHandler] - <Created LDAP principal for id cfernand and 1 attributes> 2017-07-10 13:03:14,956 INFO [org.apereo.cas.authentication. PolicyBasedAuthenticationManager] - <LdapAuthenticationHandler successfully authenticated cfernand> So it says there are no attributes in the LDAP response, however LDAP is configured to retrieve attributes and CAS intermittently releases attributes with this same exact configuration. What gives? Best regards, -- Carlos M. Fernández Enterprise Systems Manager *Saint Joseph’s University* Philadelphia PA 19131 T: +1 610 660 1501 On Mon, Jul 10, 2017 at 12:44 PM, Carlos Fernandez <[email protected]> wrote: > Good afternoon, > > We recently upgraded to CAS 5.0.5 in production and have now run into an > issue where CAS fails to authenticate users. It seems that whenever CAS > fails the authentication attempt when tries to check out a connection from > the LDAP pool and Ldaptive fails the checkout validation. This seems to > affect attribute release as well -- some of our applications depend on > specific attributes to be sent through validation but they're failing > intermittently. An excerpt from the log file follows: > > ---8<--- > 2017-07-10 12:26:33,172 WARN [org.ldaptive.pool.BlockingConnectionPool] - > <connection failed check out validation: org.ldaptive.pool.AbstractConn > ectionPool$DefaultPooledConnectionProxy@3b167a90> > 2017-07-10 12:26:33,173 ERROR [org.apereo.cas.authentication > .PolicyBasedAuthenticationManager] - <LdapAuthenticationHandler: > Unexpected LDAP error (Details: Validation of connection failed)> > 2017-07-10 12:26:33,174 WARN [org.apereo.cas.authentication > .PolicyBasedAuthenticationManager] - <Authentication has failed. > Credentials may be incorrect or CAS cannot find authentication handler that > supports [ea685774] of type [UsernamePasswordCredential], which suggests a > configuration problem.> > 2017-07-10 12:26:33,175 INFO [org.apereo.inspektr.audit.sup > port.Slf4jLoggingAuditTrailManager] - <Audit trail record BEGIN > ============================================================= > WHO: ea685774 > WHAT: Supplied credentials: [ea685774] > ACTION: AUTHENTICATION_FAILED > APPLICATION: CAS > WHEN: Mon Jul 10 12:26:33 EDT 2017 > CLIENT IP ADDRESS: 129.68.65.149 > SERVER IP ADDRESS: unknown > ============================================================= > > > > ---8<--- > > I guess we didn't run into this issue in testing because there we couldn't > generate enough load to trigger it. What's the consensus on using the > validateOnCheckout option? Should I disable it? Or perhaps I'm barking up > the wrong tree here? > > The relevant CAS properties here (comments and all) are: > > ---8<--- > cas.authn.ldap[0].type=DIRECT > cas.authn.ldap[0].ldapUrl=ldaps://axldap.sju.edu > cas.authn.ldap[0].useSsl=true > cas.authn.ldap[0].useStartTls=false > cas.authn.ldap[0].connectTimeout=5000 > cas.authn.ldap[0].baseDn=ou=people,o=sju.edu > # cas.authn.ldap[0].userFilter=uid={user} > # cas.authn.ldap[0].subtreeSearch=true > # cas.authn.ldap[0].usePasswordPolicy=true > # cas.authn.ldap[0].bindDn=cn=Directory Manager > # cas.authn.ldap[0].bindCredential=trolololo > # cas.authn.ldap[0].poolPassivator=NONE|CLOSE|BIND > cas.authn.ldap[0].poolPassivator=CLOSE > cas.authn.ldap[0].enhanceWithEntryResolver=true > cas.authn.ldap[0].dnFormat=uid=%s,ou=people,o=sju.edu > cas.authn.ldap[0].principalAttributeId=uid > #cas.authn.ldap[0].principalAttributePassword= > cas.authn.ldap[0].principalAttributeList=uid,mail, > displayName,givenName,sn,employeeNumber,udcid,pswUserName, > employeeType,departmentNumber > cas.authn.ldap[0].allowMultiplePrincipalAttributeValues=true > #cas.authn.ldap[0].additionalAttributes= > #cas.authn.ldap[0].credentialCriteria= > # cas.authn.ldap[0].saslMechanism=GSSAPI|DIGEST_MD5|CRAM_MD5|EXTERNAL > # cas.authn.ldap[0].saslMechanism=CRAM_MD5 > # cas.authn.ldap[0].saslRealm=SJU.EDU > # cas.authn.ldap[0].saslAuthorizationId= > # cas.authn.ldap[0].saslMutualAuth= > # cas.authn.ldap[0].saslQualityOfProtection= > # cas.authn.ldap[0].saslSecurityStrength= > cas.authn.ldap[0].trustCertificates=file:/etc/cas/credentials/axldap.crt > cas.authn.ldap[0].sslConfig=certificateTrust > #cas.authn.ldap[0].keystore= > #cas.authn.ldap[0].keystorePassword= > #cas.authn.ldap[0].keystoreType=JKS|JCEKS|PKCS12 > cas.authn.ldap[0].minPoolSize=10 > cas.authn.ldap[0].maxPoolSize=200 > #cas.authn.ldap[0].validateOnCheckout=true > #cas.authn.ldap[0].validatePeriodically=true > #cas.authn.ldap[0].validatePeriod=60 > cas.authn.ldap[0].failFast=false > cas.authn.ldap[0].idleTime=300 > cas.authn.ldap[0].prunePeriod=300 > cas.authn.ldap[0].blockWaitTime=300 > # cas.authn.ldap[0].providerClass=org.ldaptive.provider. > unboundid.UnboundIDProvider > cas.authn.ldap[0].allowMultipleDns=false > # cas.authn.ldap[0].passwordEncoder.type=NONE|DEFAULT|STANDARD|BCRYPT > # cas.authn.ldap[0].passwordEncoder.type=DEFAULT > # cas.authn.ldap[0].passwordEncoder.characterEncoding=UTF-8 > # cas.authn.ldap[0].passwordEncoder.encodingAlgorithm= > # cas.authn.ldap[0].passwordEncoder.secret= > # cas.authn.ldap[0].passwordEncoder.strength=16 > #cas.authn.ldap[0].principalTransformation.suffix= > #cas.authn.ldap[0].principalTransformation.caseConversion= > NONE|UPPERCASE|LOWERCASE > #cas.authn.ldap[0].principalTransformation.prefix= > cas.authn.ldap[0].passwordPolicy.enabled=false > # cas.authn.ldap[0].passwordPolicy.policyAttributes.accountLoc > ked=javax.security.auth.login.AccountLockedException > # cas.authn.ldap[0].passwordPolicy.loginFailures=5 > # cas.authn.ldap[0].passwordPolicy.warningAttributeValue= > # cas.authn.ldap[0].passwordPolicy.warningAttributeName= > # cas.authn.ldap[0].passwordPolicy.displayWarningOnMatch=true > # cas.authn.ldap[0].passwordPolicy.warnAll=true > # cas.authn.ldap[0].passwordPolicy.warningDays=30 > ---8<--- > > Thanks in advance for any advice that you can provide. > > Best regards, > -- > Carlos M. Fernández > Enterprise Systems Manager > *Saint Joseph’s University* > Philadelphia PA 19131 > T: +1 610 660 1501 > caslogs.zip <https://drive.google.com/a/sju.edu/file/d/0B-j8Pz4AXloHczFURXdhaGYwU1E/view?usp=drive_web> -- - CAS gitter chatroom: https://gitter.im/apereo/cas - CAS mailing list guidelines: https://apereo.github.io/cas/Mailing-Lists.html - CAS documentation website: https://apereo.github.io/cas - CAS project website: https://github.com/apereo/cas --- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/a/apereo.org/d/msgid/cas-user/CAE7KU87POUxTJHYGGC29e%3DkFWM2q94PNXtGV2vMF0fia075x5w%40mail.gmail.com.
