Tim,

Knowing that the same issue happens elsewhere makes me feel much better
about my sanity. Now to figure out why it happens. I have an inkling that
ldaptive is causing this, returning a failure when a connection fails
validation on checkout instead of passivating it and retrying with another
connection.

Best regards,
--
Carlos M. Fernández
Enterprise Systems Manager
*Saint Joseph’s University*
Philadelphia PA 19131
T: +1 610 660 1501

On Mon, Jul 10, 2017 at 2:02 PM, Tim McLaughlin <[email protected]>
wrote:

> This is great -- I don't have DEBUG logging turned on, but I am seeing the
> behavior where CAS 5 (I'm on 5.0.3) gets the "principal id attribute not
> available" message.
>
>
>
> In our case, it seems to work just fine for some amount of time after a
> tomcat restart, and then at some point (I'm doing some testing to see if I
> can nail down the timing), this message begins.
>
>
>
> I'm not seeing this in our Test or Dev deployments, but usage of those is
> very small compared to Production, so I'm assuming this is tied to load or
> the number of principals created or something...
>
>
>
> Tim
>
>
>
> *From: *<[email protected]> on behalf of Carlos Fernandez <
> [email protected]>
> *Reply-To: *"[email protected]" <[email protected]>
> *Date: *Monday, July 10, 2017 at 10:37
> *To: *"[email protected]" <[email protected]>
> *Subject: *[cas-user] Fwd: CAS 5.0.5 - LDAP check out validation failure
> results in failed authentication
>
>
>
> I'm attaching the debug log files here.
>
> I also found this:
>
> 2017-07-10 13:03:14,955 WARN 
> [org.apereo.cas.authentication.LdapAuthenticationHandler]
> - <The principal id attribute [uid] is not found. CAS cannot construct the
> final authenticated principal if it's unable to locate the attribute that
> is designated as the principal id. Attributes available on the LDAP entry
> are [[]]. Since principal id attribute is not available, CAS will fallback
> to construct the principal based on the provided user id: cfernand>
> 2017-07-10 13:03:14,955 DEBUG 
> [org.apereo.cas.authentication.LdapAuthenticationHandler]
> - <Created LDAP principal for id cfernand and 1 attributes>
> 2017-07-10 13:03:14,956 INFO [org.apereo.cas.authentication.
> PolicyBasedAuthenticationManager] - <LdapAuthenticationHandler
> successfully authenticated cfernand>
>
> So it says there are no attributes in the LDAP response, however LDAP is
> configured to retrieve attributes and CAS intermittently releases
> attributes with this same exact configuration. What gives?
>
> Best regards,
> --
> Carlos M. Fernández
> Enterprise Systems Manager
> *Saint Joseph’s University*
> Philadelphia PA 19131
> T: +1 610 660 1501
>
>
>
> On Mon, Jul 10, 2017 at 12:44 PM, Carlos Fernandez <[email protected]>
> wrote:
>
> Good afternoon,
>
> We recently upgraded to CAS 5.0.5 in production and have now run into an
> issue where CAS fails to authenticate users. It seems that whenever CAS
> fails the authentication attempt when tries to check out a connection from
> the LDAP pool and Ldaptive fails the checkout validation. This seems to
> affect attribute release as well -- some of our applications depend on
> specific attributes to be sent through validation but they're failing
> intermittently. An excerpt from the log file follows:
>
>
> ---8<---
> 2017-07-10 12:26:33,172 WARN [org.ldaptive.pool.BlockingConnectionPool] -
> <connection failed check out validation: org.ldaptive.pool.
> AbstractConnectionPool$DefaultPooledConnectionProxy@3b167a90>
> 2017-07-10 12:26:33,173 ERROR [org.apereo.cas.authentication.
> PolicyBasedAuthenticationManager] - <LdapAuthenticationHandler:
> Unexpected LDAP error  (Details: Validation of connection failed)>
> 2017-07-10 12:26:33,174 WARN [org.apereo.cas.authentication.
> PolicyBasedAuthenticationManager] - <Authentication has failed.
> Credentials may be incorrect or CAS cannot find authentication handler that
> supports [ea685774] of type [UsernamePasswordCredential], which suggests a
> configuration problem.>
> 2017-07-10 12:26:33,175 INFO 
> [org.apereo.inspektr.audit.support.Slf4jLoggingAuditTrailManager]
> - <Audit trail record BEGIN
> =============================================================
> WHO: ea685774
> WHAT: Supplied credentials: [ea685774]
> ACTION: AUTHENTICATION_FAILED
> APPLICATION: CAS
> WHEN: Mon Jul 10 12:26:33 EDT 2017
> CLIENT IP ADDRESS: 129.68.65.149
> SERVER IP ADDRESS: unknown
> =============================================================
>
> >
> ---8<---
>
> I guess we didn't run into this issue in testing because there we couldn't
> generate enough load to trigger it. What's the consensus on using the
> validateOnCheckout option? Should I disable it? Or perhaps I'm barking up
> the wrong tree here?
>
>
>
> The relevant CAS properties here (comments and all) are:
>
> ---8<---
> cas.authn.ldap[0].type=DIRECT
> cas.authn.ldap[0].ldapUrl=ldaps://axldap.sju.edu
> cas.authn.ldap[0].useSsl=true
> cas.authn.ldap[0].useStartTls=false
> cas.authn.ldap[0].connectTimeout=5000
> cas.authn.ldap[0].baseDn=ou=people,o=sju.edu
> # cas.authn.ldap[0].userFilter=uid={user}
> # cas.authn.ldap[0].subtreeSearch=true
> # cas.authn.ldap[0].usePasswordPolicy=true
> # cas.authn.ldap[0].bindDn=cn=Directory Manager
> # cas.authn.ldap[0].bindCredential=trolololo
> # cas.authn.ldap[0].poolPassivator=NONE|CLOSE|BIND
> cas.authn.ldap[0].poolPassivator=CLOSE
> cas.authn.ldap[0].enhanceWithEntryResolver=true
> cas.authn.ldap[0].dnFormat=uid=%s,ou=people,o=sju.edu
> cas.authn.ldap[0].principalAttributeId=uid
> #cas.authn.ldap[0].principalAttributePassword=
> cas.authn.ldap[0].principalAttributeList=uid,
> mail,displayName,givenName,sn,employeeNumber,udcid,
> pswUserName,employeeType,departmentNumber
> cas.authn.ldap[0].allowMultiplePrincipalAttributeValues=true
> #cas.authn.ldap[0].additionalAttributes=
> #cas.authn.ldap[0].credentialCriteria=
> # cas.authn.ldap[0].saslMechanism=GSSAPI|DIGEST_MD5|CRAM_MD5|EXTERNAL
> # cas.authn.ldap[0].saslMechanism=CRAM_MD5
> # cas.authn.ldap[0].saslRealm=SJU.EDU
> # cas.authn.ldap[0].saslAuthorizationId=
> # cas.authn.ldap[0].saslMutualAuth=
> # cas.authn.ldap[0].saslQualityOfProtection=
> # cas.authn.ldap[0].saslSecurityStrength=
> cas.authn.ldap[0].trustCertificates=file:/etc/cas/credentials/axldap.crt
> cas.authn.ldap[0].sslConfig=certificateTrust
> #cas.authn.ldap[0].keystore=
> #cas.authn.ldap[0].keystorePassword=
> #cas.authn.ldap[0].keystoreType=JKS|JCEKS|PKCS12
> cas.authn.ldap[0].minPoolSize=10
> cas.authn.ldap[0].maxPoolSize=200
> #cas.authn.ldap[0].validateOnCheckout=true
> #cas.authn.ldap[0].validatePeriodically=true
> #cas.authn.ldap[0].validatePeriod=60
> cas.authn.ldap[0].failFast=false
> cas.authn.ldap[0].idleTime=300
> cas.authn.ldap[0].prunePeriod=300
> cas.authn.ldap[0].blockWaitTime=300
> # cas.authn.ldap[0].providerClass=org.ldaptive.provider.unboundid.
> UnboundIDProvider
> cas.authn.ldap[0].allowMultipleDns=false
> # cas.authn.ldap[0].passwordEncoder.type=NONE|DEFAULT|STANDARD|BCRYPT
> # cas.authn.ldap[0].passwordEncoder.type=DEFAULT
> # cas.authn.ldap[0].passwordEncoder.characterEncoding=UTF-8
> # cas.authn.ldap[0].passwordEncoder.encodingAlgorithm=
> # cas.authn.ldap[0].passwordEncoder.secret=
> # cas.authn.ldap[0].passwordEncoder.strength=16
> #cas.authn.ldap[0].principalTransformation.suffix=
> #cas.authn.ldap[0].principalTransformation.caseConversion=NONE|UPPERCASE|
> LOWERCASE
> #cas.authn.ldap[0].principalTransformation.prefix=
> cas.authn.ldap[0].passwordPolicy.enabled=false
> # cas.authn.ldap[0].passwordPolicy.policyAttributes.
> accountLocked=javax.security.auth.login.AccountLockedException
> # cas.authn.ldap[0].passwordPolicy.loginFailures=5
> # cas.authn.ldap[0].passwordPolicy.warningAttributeValue=
> # cas.authn.ldap[0].passwordPolicy.warningAttributeName=
> # cas.authn.ldap[0].passwordPolicy.displayWarningOnMatch=true
> # cas.authn.ldap[0].passwordPolicy.warnAll=true
> # cas.authn.ldap[0].passwordPolicy.warningDays=30
> ---8<---
>
> Thanks in advance for any advice that you can provide.
>
> Best regards,
> --
> Carlos M. Fernández
> Enterprise Systems Manager
> *Saint Joseph’s University*
> Philadelphia PA 19131
> T: +1 610 660 1501
>
>
>
> ​
>
> * caslogs.zip
> <https://drive.google.com/a/sju.edu/file/d/0B-j8Pz4AXloHczFURXdhaGYwU1E/view?usp=drive_web>*
>
> ​
>
> --
> - CAS gitter chatroom: https://gitter.im/apereo/cas
> - CAS mailing list guidelines: https://apereo.github.io/cas/
> Mailing-Lists.html
> <http://spamburger.sju.edu/canit/urlproxy.php?_q=aHR0cHM6Ly9hcGVyZW8uZ2l0aHViLmlvL2Nhcy9NYWlsaW5nLUxpc3RzLmh0bWw%3D&_s=Y2Zlcm5hbmQ%3D&_c=77a03ca9>
> - CAS documentation website: https://apereo.github.io/cas
> <http://spamburger.sju.edu/canit/urlproxy.php?_q=aHR0cHM6Ly9hcGVyZW8uZ2l0aHViLmlvL2Nhcw%3D%3D&_s=Y2Zlcm5hbmQ%3D&_c=9d7960c0>
> - CAS project website: https://github.com/apereo/cas
> ---
> You received this message because you are subscribed to the Google Groups
> "CAS Community" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to [email protected].
> To view this discussion on the web visit https://groups.google.com/a/
> apereo.org/d/msgid/cas-user/CAE7KU87POUxTJHYGGC29e%
> 3DkFWM2q94PNXtGV2vMF0fia075x5w%40mail.gmail.com
> <https://groups.google.com/a/apereo.org/d/msgid/cas-user/CAE7KU87POUxTJHYGGC29e%3DkFWM2q94PNXtGV2vMF0fia075x5w%40mail.gmail.com?utm_medium=email&utm_source=footer>
> .
>
> --
> - CAS gitter chatroom: https://gitter.im/apereo/cas
> - CAS mailing list guidelines: https://apereo.github.io/cas/
> Mailing-Lists.html
> <http://spamburger.sju.edu/canit/urlproxy.php?_q=aHR0cHM6Ly9hcGVyZW8uZ2l0aHViLmlvL2Nhcy9NYWlsaW5nLUxpc3RzLmh0bWw%3D&_s=Y2Zlcm5hbmQ%3D&_c=77a03ca9>
> - CAS documentation website: https://apereo.github.io/cas
> <http://spamburger.sju.edu/canit/urlproxy.php?_q=aHR0cHM6Ly9hcGVyZW8uZ2l0aHViLmlvL2Nhcw%3D%3D&_s=Y2Zlcm5hbmQ%3D&_c=9d7960c0>
> - CAS project website: https://github.com/apereo/cas
> ---
> You received this message because you are subscribed to the Google Groups
> "CAS Community" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to [email protected].
> To view this discussion on the web visit https://groups.google.com/a/
> apereo.org/d/msgid/cas-user/68D97E0C-9811-4821-B741-3E463132A1A7%40wwu.edu
> <https://groups.google.com/a/apereo.org/d/msgid/cas-user/68D97E0C-9811-4821-B741-3E463132A1A7%40wwu.edu?utm_medium=email&utm_source=footer>
> .
>

-- 
- CAS gitter chatroom: https://gitter.im/apereo/cas
- CAS mailing list guidelines: https://apereo.github.io/cas/Mailing-Lists.html
- CAS documentation website: https://apereo.github.io/cas
- CAS project website: https://github.com/apereo/cas
--- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/a/apereo.org/d/msgid/cas-user/CAE7KU84z2MaQGpi5B0DfrB97N-ec7h7SD4q%3DFSiQq6YcSoTNwA%40mail.gmail.com.

Reply via email to