Tim, Knowing that the same issue happens elsewhere makes me feel much better about my sanity. Now to figure out why it happens. I have an inkling that ldaptive is causing this, returning a failure when a connection fails validation on checkout instead of passivating it and retrying with another connection.
Best regards, -- Carlos M. Fernández Enterprise Systems Manager *Saint Joseph’s University* Philadelphia PA 19131 T: +1 610 660 1501 On Mon, Jul 10, 2017 at 2:02 PM, Tim McLaughlin <[email protected]> wrote: > This is great -- I don't have DEBUG logging turned on, but I am seeing the > behavior where CAS 5 (I'm on 5.0.3) gets the "principal id attribute not > available" message. > > > > In our case, it seems to work just fine for some amount of time after a > tomcat restart, and then at some point (I'm doing some testing to see if I > can nail down the timing), this message begins. > > > > I'm not seeing this in our Test or Dev deployments, but usage of those is > very small compared to Production, so I'm assuming this is tied to load or > the number of principals created or something... > > > > Tim > > > > *From: *<[email protected]> on behalf of Carlos Fernandez < > [email protected]> > *Reply-To: *"[email protected]" <[email protected]> > *Date: *Monday, July 10, 2017 at 10:37 > *To: *"[email protected]" <[email protected]> > *Subject: *[cas-user] Fwd: CAS 5.0.5 - LDAP check out validation failure > results in failed authentication > > > > I'm attaching the debug log files here. > > I also found this: > > 2017-07-10 13:03:14,955 WARN > [org.apereo.cas.authentication.LdapAuthenticationHandler] > - <The principal id attribute [uid] is not found. CAS cannot construct the > final authenticated principal if it's unable to locate the attribute that > is designated as the principal id. Attributes available on the LDAP entry > are [[]]. Since principal id attribute is not available, CAS will fallback > to construct the principal based on the provided user id: cfernand> > 2017-07-10 13:03:14,955 DEBUG > [org.apereo.cas.authentication.LdapAuthenticationHandler] > - <Created LDAP principal for id cfernand and 1 attributes> > 2017-07-10 13:03:14,956 INFO [org.apereo.cas.authentication. > PolicyBasedAuthenticationManager] - <LdapAuthenticationHandler > successfully authenticated cfernand> > > So it says there are no attributes in the LDAP response, however LDAP is > configured to retrieve attributes and CAS intermittently releases > attributes with this same exact configuration. What gives? > > Best regards, > -- > Carlos M. Fernández > Enterprise Systems Manager > *Saint Joseph’s University* > Philadelphia PA 19131 > T: +1 610 660 1501 > > > > On Mon, Jul 10, 2017 at 12:44 PM, Carlos Fernandez <[email protected]> > wrote: > > Good afternoon, > > We recently upgraded to CAS 5.0.5 in production and have now run into an > issue where CAS fails to authenticate users. It seems that whenever CAS > fails the authentication attempt when tries to check out a connection from > the LDAP pool and Ldaptive fails the checkout validation. This seems to > affect attribute release as well -- some of our applications depend on > specific attributes to be sent through validation but they're failing > intermittently. An excerpt from the log file follows: > > > ---8<--- > 2017-07-10 12:26:33,172 WARN [org.ldaptive.pool.BlockingConnectionPool] - > <connection failed check out validation: org.ldaptive.pool. > AbstractConnectionPool$DefaultPooledConnectionProxy@3b167a90> > 2017-07-10 12:26:33,173 ERROR [org.apereo.cas.authentication. > PolicyBasedAuthenticationManager] - <LdapAuthenticationHandler: > Unexpected LDAP error (Details: Validation of connection failed)> > 2017-07-10 12:26:33,174 WARN [org.apereo.cas.authentication. > PolicyBasedAuthenticationManager] - <Authentication has failed. > Credentials may be incorrect or CAS cannot find authentication handler that > supports [ea685774] of type [UsernamePasswordCredential], which suggests a > configuration problem.> > 2017-07-10 12:26:33,175 INFO > [org.apereo.inspektr.audit.support.Slf4jLoggingAuditTrailManager] > - <Audit trail record BEGIN > ============================================================= > WHO: ea685774 > WHAT: Supplied credentials: [ea685774] > ACTION: AUTHENTICATION_FAILED > APPLICATION: CAS > WHEN: Mon Jul 10 12:26:33 EDT 2017 > CLIENT IP ADDRESS: 129.68.65.149 > SERVER IP ADDRESS: unknown > ============================================================= > > > > ---8<--- > > I guess we didn't run into this issue in testing because there we couldn't > generate enough load to trigger it. What's the consensus on using the > validateOnCheckout option? Should I disable it? Or perhaps I'm barking up > the wrong tree here? > > > > The relevant CAS properties here (comments and all) are: > > ---8<--- > cas.authn.ldap[0].type=DIRECT > cas.authn.ldap[0].ldapUrl=ldaps://axldap.sju.edu > cas.authn.ldap[0].useSsl=true > cas.authn.ldap[0].useStartTls=false > cas.authn.ldap[0].connectTimeout=5000 > cas.authn.ldap[0].baseDn=ou=people,o=sju.edu > # cas.authn.ldap[0].userFilter=uid={user} > # cas.authn.ldap[0].subtreeSearch=true > # cas.authn.ldap[0].usePasswordPolicy=true > # cas.authn.ldap[0].bindDn=cn=Directory Manager > # cas.authn.ldap[0].bindCredential=trolololo > # cas.authn.ldap[0].poolPassivator=NONE|CLOSE|BIND > cas.authn.ldap[0].poolPassivator=CLOSE > cas.authn.ldap[0].enhanceWithEntryResolver=true > cas.authn.ldap[0].dnFormat=uid=%s,ou=people,o=sju.edu > cas.authn.ldap[0].principalAttributeId=uid > #cas.authn.ldap[0].principalAttributePassword= > cas.authn.ldap[0].principalAttributeList=uid, > mail,displayName,givenName,sn,employeeNumber,udcid, > pswUserName,employeeType,departmentNumber > cas.authn.ldap[0].allowMultiplePrincipalAttributeValues=true > #cas.authn.ldap[0].additionalAttributes= > #cas.authn.ldap[0].credentialCriteria= > # cas.authn.ldap[0].saslMechanism=GSSAPI|DIGEST_MD5|CRAM_MD5|EXTERNAL > # cas.authn.ldap[0].saslMechanism=CRAM_MD5 > # cas.authn.ldap[0].saslRealm=SJU.EDU > # cas.authn.ldap[0].saslAuthorizationId= > # cas.authn.ldap[0].saslMutualAuth= > # cas.authn.ldap[0].saslQualityOfProtection= > # cas.authn.ldap[0].saslSecurityStrength= > cas.authn.ldap[0].trustCertificates=file:/etc/cas/credentials/axldap.crt > cas.authn.ldap[0].sslConfig=certificateTrust > #cas.authn.ldap[0].keystore= > #cas.authn.ldap[0].keystorePassword= > #cas.authn.ldap[0].keystoreType=JKS|JCEKS|PKCS12 > cas.authn.ldap[0].minPoolSize=10 > cas.authn.ldap[0].maxPoolSize=200 > #cas.authn.ldap[0].validateOnCheckout=true > #cas.authn.ldap[0].validatePeriodically=true > #cas.authn.ldap[0].validatePeriod=60 > cas.authn.ldap[0].failFast=false > cas.authn.ldap[0].idleTime=300 > cas.authn.ldap[0].prunePeriod=300 > cas.authn.ldap[0].blockWaitTime=300 > # cas.authn.ldap[0].providerClass=org.ldaptive.provider.unboundid. > UnboundIDProvider > cas.authn.ldap[0].allowMultipleDns=false > # cas.authn.ldap[0].passwordEncoder.type=NONE|DEFAULT|STANDARD|BCRYPT > # cas.authn.ldap[0].passwordEncoder.type=DEFAULT > # cas.authn.ldap[0].passwordEncoder.characterEncoding=UTF-8 > # cas.authn.ldap[0].passwordEncoder.encodingAlgorithm= > # cas.authn.ldap[0].passwordEncoder.secret= > # cas.authn.ldap[0].passwordEncoder.strength=16 > #cas.authn.ldap[0].principalTransformation.suffix= > #cas.authn.ldap[0].principalTransformation.caseConversion=NONE|UPPERCASE| > LOWERCASE > #cas.authn.ldap[0].principalTransformation.prefix= > cas.authn.ldap[0].passwordPolicy.enabled=false > # cas.authn.ldap[0].passwordPolicy.policyAttributes. > accountLocked=javax.security.auth.login.AccountLockedException > # cas.authn.ldap[0].passwordPolicy.loginFailures=5 > # cas.authn.ldap[0].passwordPolicy.warningAttributeValue= > # cas.authn.ldap[0].passwordPolicy.warningAttributeName= > # cas.authn.ldap[0].passwordPolicy.displayWarningOnMatch=true > # cas.authn.ldap[0].passwordPolicy.warnAll=true > # cas.authn.ldap[0].passwordPolicy.warningDays=30 > ---8<--- > > Thanks in advance for any advice that you can provide. > > Best regards, > -- > Carlos M. Fernández > Enterprise Systems Manager > *Saint Joseph’s University* > Philadelphia PA 19131 > T: +1 610 660 1501 > > > > > > * caslogs.zip > <https://drive.google.com/a/sju.edu/file/d/0B-j8Pz4AXloHczFURXdhaGYwU1E/view?usp=drive_web>* > > > > -- > - CAS gitter chatroom: https://gitter.im/apereo/cas > - CAS mailing list guidelines: https://apereo.github.io/cas/ > Mailing-Lists.html > <http://spamburger.sju.edu/canit/urlproxy.php?_q=aHR0cHM6Ly9hcGVyZW8uZ2l0aHViLmlvL2Nhcy9NYWlsaW5nLUxpc3RzLmh0bWw%3D&_s=Y2Zlcm5hbmQ%3D&_c=77a03ca9> > - CAS documentation website: https://apereo.github.io/cas > <http://spamburger.sju.edu/canit/urlproxy.php?_q=aHR0cHM6Ly9hcGVyZW8uZ2l0aHViLmlvL2Nhcw%3D%3D&_s=Y2Zlcm5hbmQ%3D&_c=9d7960c0> > - CAS project website: https://github.com/apereo/cas > --- > You received this message because you are subscribed to the Google Groups > "CAS Community" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to [email protected]. > To view this discussion on the web visit https://groups.google.com/a/ > apereo.org/d/msgid/cas-user/CAE7KU87POUxTJHYGGC29e% > 3DkFWM2q94PNXtGV2vMF0fia075x5w%40mail.gmail.com > <https://groups.google.com/a/apereo.org/d/msgid/cas-user/CAE7KU87POUxTJHYGGC29e%3DkFWM2q94PNXtGV2vMF0fia075x5w%40mail.gmail.com?utm_medium=email&utm_source=footer> > . > > -- > - CAS gitter chatroom: https://gitter.im/apereo/cas > - CAS mailing list guidelines: https://apereo.github.io/cas/ > Mailing-Lists.html > <http://spamburger.sju.edu/canit/urlproxy.php?_q=aHR0cHM6Ly9hcGVyZW8uZ2l0aHViLmlvL2Nhcy9NYWlsaW5nLUxpc3RzLmh0bWw%3D&_s=Y2Zlcm5hbmQ%3D&_c=77a03ca9> > - CAS documentation website: https://apereo.github.io/cas > <http://spamburger.sju.edu/canit/urlproxy.php?_q=aHR0cHM6Ly9hcGVyZW8uZ2l0aHViLmlvL2Nhcw%3D%3D&_s=Y2Zlcm5hbmQ%3D&_c=9d7960c0> > - CAS project website: https://github.com/apereo/cas > --- > You received this message because you are subscribed to the Google Groups > "CAS Community" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to [email protected]. > To view this discussion on the web visit https://groups.google.com/a/ > apereo.org/d/msgid/cas-user/68D97E0C-9811-4821-B741-3E463132A1A7%40wwu.edu > <https://groups.google.com/a/apereo.org/d/msgid/cas-user/68D97E0C-9811-4821-B741-3E463132A1A7%40wwu.edu?utm_medium=email&utm_source=footer> > . > -- - CAS gitter chatroom: https://gitter.im/apereo/cas - CAS mailing list guidelines: https://apereo.github.io/cas/Mailing-Lists.html - CAS documentation website: https://apereo.github.io/cas - CAS project website: https://github.com/apereo/cas --- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/a/apereo.org/d/msgid/cas-user/CAE7KU84z2MaQGpi5B0DfrB97N-ec7h7SD4q%3DFSiQq6YcSoTNwA%40mail.gmail.com.
