I found a thread in the Google group for ldaptive that describes a scenario similar to ours. Could anyone confirm that it's related?
https://groups.google.com/forum/#!topic/ldaptive/6pF-36w2gyI Best regards, -- Carlos M. Fernández Enterprise Systems Manager *Saint Joseph’s University* Philadelphia PA 19131 T: +1 610 660 1501 On Mon, Jul 10, 2017 at 2:16 PM, Carlos Fernandez <[email protected]> wrote: > Tim, > > Knowing that the same issue happens elsewhere makes me feel much better > about my sanity. Now to figure out why it happens. I have an inkling that > ldaptive is causing this, returning a failure when a connection fails > validation on checkout instead of passivating it and retrying with another > connection. > > Best regards, > -- > Carlos M. Fernández > Enterprise Systems Manager > *Saint Joseph’s University* > Philadelphia PA 19131 > T: +1 610 660 1501 > > On Mon, Jul 10, 2017 at 2:02 PM, Tim McLaughlin <[email protected]> > wrote: > >> This is great -- I don't have DEBUG logging turned on, but I am seeing >> the behavior where CAS 5 (I'm on 5.0.3) gets the "principal id attribute >> not available" message. >> >> >> >> In our case, it seems to work just fine for some amount of time after a >> tomcat restart, and then at some point (I'm doing some testing to see if I >> can nail down the timing), this message begins. >> >> >> >> I'm not seeing this in our Test or Dev deployments, but usage of those is >> very small compared to Production, so I'm assuming this is tied to load or >> the number of principals created or something... >> >> >> >> Tim >> >> >> >> *From: *<[email protected]> on behalf of Carlos Fernandez < >> [email protected]> >> *Reply-To: *"[email protected]" <[email protected]> >> *Date: *Monday, July 10, 2017 at 10:37 >> *To: *"[email protected]" <[email protected]> >> *Subject: *[cas-user] Fwd: CAS 5.0.5 - LDAP check out validation failure >> results in failed authentication >> >> >> >> I'm attaching the debug log files here. >> >> I also found this: >> >> 2017-07-10 13:03:14,955 WARN >> [org.apereo.cas.authentication.LdapAuthenticationHandler] >> - <The principal id attribute [uid] is not found. CAS cannot construct the >> final authenticated principal if it's unable to locate the attribute that >> is designated as the principal id. Attributes available on the LDAP entry >> are [[]]. Since principal id attribute is not available, CAS will fallback >> to construct the principal based on the provided user id: cfernand> >> 2017-07-10 13:03:14,955 DEBUG >> [org.apereo.cas.authentication.LdapAuthenticationHandler] >> - <Created LDAP principal for id cfernand and 1 attributes> >> 2017-07-10 13:03:14,956 INFO [org.apereo.cas.authentication >> .PolicyBasedAuthenticationManager] - <LdapAuthenticationHandler >> successfully authenticated cfernand> >> >> So it says there are no attributes in the LDAP response, however LDAP is >> configured to retrieve attributes and CAS intermittently releases >> attributes with this same exact configuration. What gives? >> >> Best regards, >> -- >> Carlos M. Fernández >> Enterprise Systems Manager >> *Saint Joseph’s University* >> Philadelphia PA 19131 >> T: +1 610 660 1501 >> >> >> >> On Mon, Jul 10, 2017 at 12:44 PM, Carlos Fernandez <[email protected]> >> wrote: >> >> Good afternoon, >> >> We recently upgraded to CAS 5.0.5 in production and have now run into an >> issue where CAS fails to authenticate users. It seems that whenever CAS >> fails the authentication attempt when tries to check out a connection from >> the LDAP pool and Ldaptive fails the checkout validation. This seems to >> affect attribute release as well -- some of our applications depend on >> specific attributes to be sent through validation but they're failing >> intermittently. An excerpt from the log file follows: >> >> >> ---8<--- >> 2017-07-10 12:26:33,172 WARN [org.ldaptive.pool.BlockingConnectionPool] >> - <connection failed check out validation: org.ldaptive.pool.AbstractConn >> ectionPool$DefaultPooledConnectionProxy@3b167a90> >> 2017-07-10 12:26:33,173 ERROR [org.apereo.cas.authentication >> .PolicyBasedAuthenticationManager] - <LdapAuthenticationHandler: >> Unexpected LDAP error (Details: Validation of connection failed)> >> 2017-07-10 12:26:33,174 WARN [org.apereo.cas.authentication >> .PolicyBasedAuthenticationManager] - <Authentication has failed. >> Credentials may be incorrect or CAS cannot find authentication handler that >> supports [ea685774] of type [UsernamePasswordCredential], which suggests a >> configuration problem.> >> 2017-07-10 12:26:33,175 INFO [org.apereo.inspektr.audit.sup >> port.Slf4jLoggingAuditTrailManager] - <Audit trail record BEGIN >> ============================================================= >> WHO: ea685774 >> WHAT: Supplied credentials: [ea685774] >> ACTION: AUTHENTICATION_FAILED >> APPLICATION: CAS >> WHEN: Mon Jul 10 12:26:33 EDT 2017 >> CLIENT IP ADDRESS: 129.68.65.149 >> SERVER IP ADDRESS: unknown >> ============================================================= >> >> > >> ---8<--- >> >> I guess we didn't run into this issue in testing because there we >> couldn't generate enough load to trigger it. What's the consensus on using >> the validateOnCheckout option? Should I disable it? Or perhaps I'm barking >> up the wrong tree here? >> >> >> >> The relevant CAS properties here (comments and all) are: >> >> ---8<--- >> cas.authn.ldap[0].type=DIRECT >> cas.authn.ldap[0].ldapUrl=ldaps://axldap.sju.edu >> cas.authn.ldap[0].useSsl=true >> cas.authn.ldap[0].useStartTls=false >> cas.authn.ldap[0].connectTimeout=5000 >> cas.authn.ldap[0].baseDn=ou=people,o=sju.edu >> # cas.authn.ldap[0].userFilter=uid={user} >> # cas.authn.ldap[0].subtreeSearch=true >> # cas.authn.ldap[0].usePasswordPolicy=true >> # cas.authn.ldap[0].bindDn=cn=Directory Manager >> # cas.authn.ldap[0].bindCredential=trolololo >> # cas.authn.ldap[0].poolPassivator=NONE|CLOSE|BIND >> cas.authn.ldap[0].poolPassivator=CLOSE >> cas.authn.ldap[0].enhanceWithEntryResolver=true >> cas.authn.ldap[0].dnFormat=uid=%s,ou=people,o=sju.edu >> cas.authn.ldap[0].principalAttributeId=uid >> #cas.authn.ldap[0].principalAttributePassword= >> cas.authn.ldap[0].principalAttributeList=uid,mail, >> displayName,givenName,sn,employeeNumber,udcid,pswUserName, >> employeeType,departmentNumber >> cas.authn.ldap[0].allowMultiplePrincipalAttributeValues=true >> #cas.authn.ldap[0].additionalAttributes= >> #cas.authn.ldap[0].credentialCriteria= >> # cas.authn.ldap[0].saslMechanism=GSSAPI|DIGEST_MD5|CRAM_MD5|EXTERNAL >> # cas.authn.ldap[0].saslMechanism=CRAM_MD5 >> # cas.authn.ldap[0].saslRealm=SJU.EDU >> # cas.authn.ldap[0].saslAuthorizationId= >> # cas.authn.ldap[0].saslMutualAuth= >> # cas.authn.ldap[0].saslQualityOfProtection= >> # cas.authn.ldap[0].saslSecurityStrength= >> cas.authn.ldap[0].trustCertificates=file:/etc/cas/credentials/axldap.crt >> cas.authn.ldap[0].sslConfig=certificateTrust >> #cas.authn.ldap[0].keystore= >> #cas.authn.ldap[0].keystorePassword= >> #cas.authn.ldap[0].keystoreType=JKS|JCEKS|PKCS12 >> cas.authn.ldap[0].minPoolSize=10 >> cas.authn.ldap[0].maxPoolSize=200 >> #cas.authn.ldap[0].validateOnCheckout=true >> #cas.authn.ldap[0].validatePeriodically=true >> #cas.authn.ldap[0].validatePeriod=60 >> cas.authn.ldap[0].failFast=false >> cas.authn.ldap[0].idleTime=300 >> cas.authn.ldap[0].prunePeriod=300 >> cas.authn.ldap[0].blockWaitTime=300 >> # cas.authn.ldap[0].providerClass=org.ldaptive.provider. >> unboundid.UnboundIDProvider >> cas.authn.ldap[0].allowMultipleDns=false >> # cas.authn.ldap[0].passwordEncoder.type=NONE|DEFAULT|STANDARD|BCRYPT >> # cas.authn.ldap[0].passwordEncoder.type=DEFAULT >> # cas.authn.ldap[0].passwordEncoder.characterEncoding=UTF-8 >> # cas.authn.ldap[0].passwordEncoder.encodingAlgorithm= >> # cas.authn.ldap[0].passwordEncoder.secret= >> # cas.authn.ldap[0].passwordEncoder.strength=16 >> #cas.authn.ldap[0].principalTransformation.suffix= >> #cas.authn.ldap[0].principalTransformation.caseConversion= >> NONE|UPPERCASE|LOWERCASE >> #cas.authn.ldap[0].principalTransformation.prefix= >> cas.authn.ldap[0].passwordPolicy.enabled=false >> # cas.authn.ldap[0].passwordPolicy.policyAttributes.accountLoc >> ked=javax.security.auth.login.AccountLockedException >> # cas.authn.ldap[0].passwordPolicy.loginFailures=5 >> # cas.authn.ldap[0].passwordPolicy.warningAttributeValue= >> # cas.authn.ldap[0].passwordPolicy.warningAttributeName= >> # cas.authn.ldap[0].passwordPolicy.displayWarningOnMatch=true >> # cas.authn.ldap[0].passwordPolicy.warnAll=true >> # cas.authn.ldap[0].passwordPolicy.warningDays=30 >> ---8<--- >> >> Thanks in advance for any advice that you can provide. >> >> Best regards, >> -- >> Carlos M. Fernández >> Enterprise Systems Manager >> *Saint Joseph’s University* >> Philadelphia PA 19131 >> T: +1 610 660 1501 >> >> >> >> >> >> * caslogs.zip >> <https://drive.google.com/a/sju.edu/file/d/0B-j8Pz4AXloHczFURXdhaGYwU1E/view?usp=drive_web>* >> >> >> >> -- >> - CAS gitter chatroom: https://gitter.im/apereo/cas >> - CAS mailing list guidelines: https://apereo.github.io/cas/M >> ailing-Lists.html >> <http://spamburger.sju.edu/canit/urlproxy.php?_q=aHR0cHM6Ly9hcGVyZW8uZ2l0aHViLmlvL2Nhcy9NYWlsaW5nLUxpc3RzLmh0bWw%3D&_s=Y2Zlcm5hbmQ%3D&_c=77a03ca9> >> - CAS documentation website: https://apereo.github.io/cas >> <http://spamburger.sju.edu/canit/urlproxy.php?_q=aHR0cHM6Ly9hcGVyZW8uZ2l0aHViLmlvL2Nhcw%3D%3D&_s=Y2Zlcm5hbmQ%3D&_c=9d7960c0> >> - CAS project website: https://github.com/apereo/cas >> --- >> You received this message because you are subscribed to the Google Groups >> "CAS Community" group. >> To unsubscribe from this group and stop receiving emails from it, send an >> email to [email protected]. >> To view this discussion on the web visit https://groups.google.com/a/ap >> ereo.org/d/msgid/cas-user/CAE7KU87POUxTJHYGGC29e%3DkFWM2q94P >> NXtGV2vMF0fia075x5w%40mail.gmail.com >> <https://groups.google.com/a/apereo.org/d/msgid/cas-user/CAE7KU87POUxTJHYGGC29e%3DkFWM2q94PNXtGV2vMF0fia075x5w%40mail.gmail.com?utm_medium=email&utm_source=footer> >> . >> >> -- >> - CAS gitter chatroom: https://gitter.im/apereo/cas >> - CAS mailing list guidelines: https://apereo.github.io/cas/M >> ailing-Lists.html >> <http://spamburger.sju.edu/canit/urlproxy.php?_q=aHR0cHM6Ly9hcGVyZW8uZ2l0aHViLmlvL2Nhcy9NYWlsaW5nLUxpc3RzLmh0bWw%3D&_s=Y2Zlcm5hbmQ%3D&_c=77a03ca9> >> - CAS documentation website: https://apereo.github.io/cas >> <http://spamburger.sju.edu/canit/urlproxy.php?_q=aHR0cHM6Ly9hcGVyZW8uZ2l0aHViLmlvL2Nhcw%3D%3D&_s=Y2Zlcm5hbmQ%3D&_c=9d7960c0> >> - CAS project website: https://github.com/apereo/cas >> --- >> You received this message because you are subscribed to the Google Groups >> "CAS Community" group. >> To unsubscribe from this group and stop receiving emails from it, send an >> email to [email protected]. >> To view this discussion on the web visit https://groups.google.com/a/ap >> ereo.org/d/msgid/cas-user/68D97E0C-9811-4821-B741-3E463132A1A7%40wwu.edu >> <https://groups.google.com/a/apereo.org/d/msgid/cas-user/68D97E0C-9811-4821-B741-3E463132A1A7%40wwu.edu?utm_medium=email&utm_source=footer> >> . >> > > -- - CAS gitter chatroom: https://gitter.im/apereo/cas - CAS mailing list guidelines: https://apereo.github.io/cas/Mailing-Lists.html - CAS documentation website: https://apereo.github.io/cas - CAS project website: https://github.com/apereo/cas --- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/a/apereo.org/d/msgid/cas-user/CAE7KU84s0%2B9hNJE031GxtJFqe5uowygwPSEdGXwfTf4ZKkEw%2BQ%40mail.gmail.com.
