Hello Rob, 
I have an extra question on this thread.  
On the client side, ldap_search request was triggered periodically and in the 
situation of large host group such as 3k  members exceeded, ldap latency was 
happening. In our client configuration, ldap_search_timeout is 6 sec by 
default.  
In this  latency situation, ldap search was failed by timeout( 6sec ) on the 
client side and it causes ldap disconnection. 

Q. what/when trigger ldap search in client side?  
In our ipa client, it has krb5_lifetime / ldap_connection_expire_time  24h, so 
I thought ldap search will be triggered every 24h, 
but ldap search was triggered continuously.   Is there another configuration to 
control ldap search? 
--
_______________________________________________
FreeIPA-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://pagure.io/fedora-infrastructure/new_issue

Reply via email to