OK, now I have something that tells me that I should not be seeing this
issue.

According to https://groups.google.com/d/topic/jasig-cas-user/4uXY5b38q5o,
this issue was reported in https://github.com/apereo/cas/issues/2443 and
fixed in
https://github.com/apereo/cas/commit/50d2bec8d33aa03fd7ed9ac1846f108bc90e128c
for the 5.0.4 release provided I use a passivator (if I read it correctly).
I specified the CLOSE passivator in the config, but we're still seeing the
same behavior in 5.0.5 as reported earlier in the Github issue. Very
confusing.


Best regards,
--
Carlos M. Fernández
Enterprise Systems Manager
*Saint Joseph’s University*
Philadelphia PA 19131
T: +1 610 660 1501

On Mon, Jul 10, 2017 at 3:08 PM, Carlos Fernandez <[email protected]> wrote:

> I found a thread in the Google group for ldaptive that describes a
> scenario similar to ours. Could anyone confirm that it's related?
>
> https://groups.google.com/forum/#!topic/ldaptive/6pF-36w2gyI
>
> Best regards,
> --
> Carlos M. Fernández
> Enterprise Systems Manager
> *Saint Joseph’s University*
> Philadelphia PA 19131
> T: +1 610 660 1501
>
> On Mon, Jul 10, 2017 at 2:16 PM, Carlos Fernandez <[email protected]>
> wrote:
>
>> Tim,
>>
>> Knowing that the same issue happens elsewhere makes me feel much better
>> about my sanity. Now to figure out why it happens. I have an inkling that
>> ldaptive is causing this, returning a failure when a connection fails
>> validation on checkout instead of passivating it and retrying with another
>> connection.
>>
>> Best regards,
>> --
>> Carlos M. Fernández
>> Enterprise Systems Manager
>> *Saint Joseph’s University*
>> Philadelphia PA 19131
>> T: +1 610 660 1501
>>
>> On Mon, Jul 10, 2017 at 2:02 PM, Tim McLaughlin <[email protected]>
>> wrote:
>>
>>> This is great -- I don't have DEBUG logging turned on, but I am seeing
>>> the behavior where CAS 5 (I'm on 5.0.3) gets the "principal id attribute
>>> not available" message.
>>>
>>>
>>>
>>> In our case, it seems to work just fine for some amount of time after a
>>> tomcat restart, and then at some point (I'm doing some testing to see if I
>>> can nail down the timing), this message begins.
>>>
>>>
>>>
>>> I'm not seeing this in our Test or Dev deployments, but usage of those
>>> is very small compared to Production, so I'm assuming this is tied to load
>>> or the number of principals created or something...
>>>
>>>
>>>
>>> Tim
>>>
>>>
>>>
>>> *From: *<[email protected]> on behalf of Carlos Fernandez <
>>> [email protected]>
>>> *Reply-To: *"[email protected]" <[email protected]>
>>> *Date: *Monday, July 10, 2017 at 10:37
>>> *To: *"[email protected]" <[email protected]>
>>> *Subject: *[cas-user] Fwd: CAS 5.0.5 - LDAP check out validation
>>> failure results in failed authentication
>>>
>>>
>>>
>>> I'm attaching the debug log files here.
>>>
>>> I also found this:
>>>
>>> 2017-07-10 13:03:14,955 WARN 
>>> [org.apereo.cas.authentication.LdapAuthenticationHandler]
>>> - <The principal id attribute [uid] is not found. CAS cannot construct the
>>> final authenticated principal if it's unable to locate the attribute that
>>> is designated as the principal id. Attributes available on the LDAP entry
>>> are [[]]. Since principal id attribute is not available, CAS will fallback
>>> to construct the principal based on the provided user id: cfernand>
>>> 2017-07-10 13:03:14,955 DEBUG 
>>> [org.apereo.cas.authentication.LdapAuthenticationHandler]
>>> - <Created LDAP principal for id cfernand and 1 attributes>
>>> 2017-07-10 13:03:14,956 INFO [org.apereo.cas.authentication
>>> .PolicyBasedAuthenticationManager] - <LdapAuthenticationHandler
>>> successfully authenticated cfernand>
>>>
>>> So it says there are no attributes in the LDAP response, however LDAP is
>>> configured to retrieve attributes and CAS intermittently releases
>>> attributes with this same exact configuration. What gives?
>>>
>>> Best regards,
>>> --
>>> Carlos M. Fernández
>>> Enterprise Systems Manager
>>> *Saint Joseph’s University*
>>> Philadelphia PA 19131
>>> T: +1 610 660 1501
>>>
>>>
>>>
>>> On Mon, Jul 10, 2017 at 12:44 PM, Carlos Fernandez <[email protected]>
>>> wrote:
>>>
>>> Good afternoon,
>>>
>>> We recently upgraded to CAS 5.0.5 in production and have now run into an
>>> issue where CAS fails to authenticate users. It seems that whenever CAS
>>> fails the authentication attempt when tries to check out a connection from
>>> the LDAP pool and Ldaptive fails the checkout validation. This seems to
>>> affect attribute release as well -- some of our applications depend on
>>> specific attributes to be sent through validation but they're failing
>>> intermittently. An excerpt from the log file follows:
>>>
>>>
>>> ---8<---
>>> 2017-07-10 12:26:33,172 WARN [org.ldaptive.pool.BlockingConnectionPool]
>>> - <connection failed check out validation: org.ldaptive.pool.AbstractConn
>>> ectionPool$DefaultPooledConnectionProxy@3b167a90>
>>> 2017-07-10 12:26:33,173 ERROR [org.apereo.cas.authentication
>>> .PolicyBasedAuthenticationManager] - <LdapAuthenticationHandler:
>>> Unexpected LDAP error  (Details: Validation of connection failed)>
>>> 2017-07-10 12:26:33,174 WARN [org.apereo.cas.authentication
>>> .PolicyBasedAuthenticationManager] - <Authentication has failed.
>>> Credentials may be incorrect or CAS cannot find authentication handler that
>>> supports [ea685774] of type [UsernamePasswordCredential], which suggests a
>>> configuration problem.>
>>> 2017-07-10 12:26:33,175 INFO [org.apereo.inspektr.audit.sup
>>> port.Slf4jLoggingAuditTrailManager] - <Audit trail record BEGIN
>>> =============================================================
>>> WHO: ea685774
>>> WHAT: Supplied credentials: [ea685774]
>>> ACTION: AUTHENTICATION_FAILED
>>> APPLICATION: CAS
>>> WHEN: Mon Jul 10 12:26:33 EDT 2017
>>> CLIENT IP ADDRESS: 129.68.65.149
>>> SERVER IP ADDRESS: unknown
>>> =============================================================
>>>
>>> >
>>> ---8<---
>>>
>>> I guess we didn't run into this issue in testing because there we
>>> couldn't generate enough load to trigger it. What's the consensus on using
>>> the validateOnCheckout option? Should I disable it? Or perhaps I'm barking
>>> up the wrong tree here?
>>>
>>>
>>>
>>> The relevant CAS properties here (comments and all) are:
>>>
>>> ---8<---
>>> cas.authn.ldap[0].type=DIRECT
>>> cas.authn.ldap[0].ldapUrl=ldaps://axldap.sju.edu
>>> cas.authn.ldap[0].useSsl=true
>>> cas.authn.ldap[0].useStartTls=false
>>> cas.authn.ldap[0].connectTimeout=5000
>>> cas.authn.ldap[0].baseDn=ou=people,o=sju.edu
>>> # cas.authn.ldap[0].userFilter=uid={user}
>>> # cas.authn.ldap[0].subtreeSearch=true
>>> # cas.authn.ldap[0].usePasswordPolicy=true
>>> # cas.authn.ldap[0].bindDn=cn=Directory Manager
>>> # cas.authn.ldap[0].bindCredential=trolololo
>>> # cas.authn.ldap[0].poolPassivator=NONE|CLOSE|BIND
>>> cas.authn.ldap[0].poolPassivator=CLOSE
>>> cas.authn.ldap[0].enhanceWithEntryResolver=true
>>> cas.authn.ldap[0].dnFormat=uid=%s,ou=people,o=sju.edu
>>> cas.authn.ldap[0].principalAttributeId=uid
>>> #cas.authn.ldap[0].principalAttributePassword=
>>> cas.authn.ldap[0].principalAttributeList=uid,mail,displayNam
>>> e,givenName,sn,employeeNumber,udcid,pswUserName,employeeType
>>> ,departmentNumber
>>> cas.authn.ldap[0].allowMultiplePrincipalAttributeValues=true
>>> #cas.authn.ldap[0].additionalAttributes=
>>> #cas.authn.ldap[0].credentialCriteria=
>>> # cas.authn.ldap[0].saslMechanism=GSSAPI|DIGEST_MD5|CRAM_MD5|EXTERNAL
>>> # cas.authn.ldap[0].saslMechanism=CRAM_MD5
>>> # cas.authn.ldap[0].saslRealm=SJU.EDU
>>> # cas.authn.ldap[0].saslAuthorizationId=
>>> # cas.authn.ldap[0].saslMutualAuth=
>>> # cas.authn.ldap[0].saslQualityOfProtection=
>>> # cas.authn.ldap[0].saslSecurityStrength=
>>> cas.authn.ldap[0].trustCertificates=file:/etc/cas/credentials/axldap.crt
>>> cas.authn.ldap[0].sslConfig=certificateTrust
>>> #cas.authn.ldap[0].keystore=
>>> #cas.authn.ldap[0].keystorePassword=
>>> #cas.authn.ldap[0].keystoreType=JKS|JCEKS|PKCS12
>>> cas.authn.ldap[0].minPoolSize=10
>>> cas.authn.ldap[0].maxPoolSize=200
>>> #cas.authn.ldap[0].validateOnCheckout=true
>>> #cas.authn.ldap[0].validatePeriodically=true
>>> #cas.authn.ldap[0].validatePeriod=60
>>> cas.authn.ldap[0].failFast=false
>>> cas.authn.ldap[0].idleTime=300
>>> cas.authn.ldap[0].prunePeriod=300
>>> cas.authn.ldap[0].blockWaitTime=300
>>> # cas.authn.ldap[0].providerClass=org.ldaptive.provider.unboun
>>> did.UnboundIDProvider
>>> cas.authn.ldap[0].allowMultipleDns=false
>>> # cas.authn.ldap[0].passwordEncoder.type=NONE|DEFAULT|STANDARD|BCRYPT
>>> # cas.authn.ldap[0].passwordEncoder.type=DEFAULT
>>> # cas.authn.ldap[0].passwordEncoder.characterEncoding=UTF-8
>>> # cas.authn.ldap[0].passwordEncoder.encodingAlgorithm=
>>> # cas.authn.ldap[0].passwordEncoder.secret=
>>> # cas.authn.ldap[0].passwordEncoder.strength=16
>>> #cas.authn.ldap[0].principalTransformation.suffix=
>>> #cas.authn.ldap[0].principalTransformation.caseConversion=NO
>>> NE|UPPERCASE|LOWERCASE
>>> #cas.authn.ldap[0].principalTransformation.prefix=
>>> cas.authn.ldap[0].passwordPolicy.enabled=false
>>> # cas.authn.ldap[0].passwordPolicy.policyAttributes.accountLoc
>>> ked=javax.security.auth.login.AccountLockedException
>>> # cas.authn.ldap[0].passwordPolicy.loginFailures=5
>>> # cas.authn.ldap[0].passwordPolicy.warningAttributeValue=
>>> # cas.authn.ldap[0].passwordPolicy.warningAttributeName=
>>> # cas.authn.ldap[0].passwordPolicy.displayWarningOnMatch=true
>>> # cas.authn.ldap[0].passwordPolicy.warnAll=true
>>> # cas.authn.ldap[0].passwordPolicy.warningDays=30
>>> ---8<---
>>>
>>> Thanks in advance for any advice that you can provide.
>>>
>>> Best regards,
>>> --
>>> Carlos M. Fernández
>>> Enterprise Systems Manager
>>> *Saint Joseph’s University*
>>> Philadelphia PA 19131
>>> T: +1 610 660 1501
>>>
>>>
>>>
>>> ​
>>>
>>> * caslogs.zip
>>> <https://drive.google.com/a/sju.edu/file/d/0B-j8Pz4AXloHczFURXdhaGYwU1E/view?usp=drive_web>*
>>>
>>> ​
>>>
>>> --
>>> - CAS gitter chatroom: https://gitter.im/apereo/cas
>>> - CAS mailing list guidelines: https://apereo.github.io/cas/M
>>> ailing-Lists.html
>>> <http://spamburger.sju.edu/canit/urlproxy.php?_q=aHR0cHM6Ly9hcGVyZW8uZ2l0aHViLmlvL2Nhcy9NYWlsaW5nLUxpc3RzLmh0bWw%3D&_s=Y2Zlcm5hbmQ%3D&_c=77a03ca9>
>>> - CAS documentation website: https://apereo.github.io/cas
>>> <http://spamburger.sju.edu/canit/urlproxy.php?_q=aHR0cHM6Ly9hcGVyZW8uZ2l0aHViLmlvL2Nhcw%3D%3D&_s=Y2Zlcm5hbmQ%3D&_c=9d7960c0>
>>> - CAS project website: https://github.com/apereo/cas
>>> ---
>>> You received this message because you are subscribed to the Google
>>> Groups "CAS Community" group.
>>> To unsubscribe from this group and stop receiving emails from it, send
>>> an email to [email protected].
>>> To view this discussion on the web visit https://groups.google.com/a/ap
>>> ereo.org/d/msgid/cas-user/CAE7KU87POUxTJHYGGC29e%3DkFWM2q94P
>>> NXtGV2vMF0fia075x5w%40mail.gmail.com
>>> <https://groups.google.com/a/apereo.org/d/msgid/cas-user/CAE7KU87POUxTJHYGGC29e%3DkFWM2q94PNXtGV2vMF0fia075x5w%40mail.gmail.com?utm_medium=email&utm_source=footer>
>>> .
>>>
>>> --
>>> - CAS gitter chatroom: https://gitter.im/apereo/cas
>>> - CAS mailing list guidelines: https://apereo.github.io/cas/M
>>> ailing-Lists.html
>>> <http://spamburger.sju.edu/canit/urlproxy.php?_q=aHR0cHM6Ly9hcGVyZW8uZ2l0aHViLmlvL2Nhcy9NYWlsaW5nLUxpc3RzLmh0bWw%3D&_s=Y2Zlcm5hbmQ%3D&_c=77a03ca9>
>>> - CAS documentation website: https://apereo.github.io/cas
>>> <http://spamburger.sju.edu/canit/urlproxy.php?_q=aHR0cHM6Ly9hcGVyZW8uZ2l0aHViLmlvL2Nhcw%3D%3D&_s=Y2Zlcm5hbmQ%3D&_c=9d7960c0>
>>> - CAS project website: https://github.com/apereo/cas
>>> ---
>>> You received this message because you are subscribed to the Google
>>> Groups "CAS Community" group.
>>> To unsubscribe from this group and stop receiving emails from it, send
>>> an email to [email protected].
>>> To view this discussion on the web visit https://groups.google.com/a/ap
>>> ereo.org/d/msgid/cas-user/68D97E0C-9811-4821-B741-3E463132A1A7%40wwu.edu
>>> <https://groups.google.com/a/apereo.org/d/msgid/cas-user/68D97E0C-9811-4821-B741-3E463132A1A7%40wwu.edu?utm_medium=email&utm_source=footer>
>>> .
>>>
>>
>>
>

-- 
- CAS gitter chatroom: https://gitter.im/apereo/cas
- CAS mailing list guidelines: https://apereo.github.io/cas/Mailing-Lists.html
- CAS documentation website: https://apereo.github.io/cas
- CAS project website: https://github.com/apereo/cas
--- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/a/apereo.org/d/msgid/cas-user/CAE7KU87xd5oSOx0WuudYeVEAYAOg07m_aTgRj%2Bd%3D5OYSEZMxVA%40mail.gmail.com.

Reply via email to